You can verify this yourself. Get an old laptop to act as a wifi hotspot and forward traffic over usb ethernet adapter to your actual router. Then run tcpdump on the computer. You will see the multitude of phone-home traffic.
You can verify this yourself. Get an old laptop to act as a wifi hotspot and forward traffic over usb ethernet adapter to your actual router. Then run tcpdump on the computer. You will see the multitude of phone-home traffic.
> As it turned out, this behavior is on purpose. There’s an explicit whitelist that allows certain macOS services to bypass any third party firewalls and to communicate on the Internet without being even noticed by the user. A hole in the wall.
Was remediated later, but shows there is precedent.
Also keep in mind that https://www.obdev.at/blog/a-hole-in-the-wall/ and its subsequent patch https://support.apple.com/en-us/102445 refers to things that bypass the firewall. There are things on your Mac that simply won't function if you block them from phoning home, making your OS an unusable mess.
What is "root" in macOS is more or less a power user role. Apple took away the true ability to operate as root a long time ago with System Integrity Protection which walls off the critical parts of the OS from the user entirely.
Unfortunately, SIP also restricts basic system functions that are trivial in other OSes. Apple made this very difficult, and MS would have loved to do this in Vista had they not received the backlash that they did.
For tech-aware people, it is probably not necessary indeed. However, given that now “tech-aware” people are running completely random and unvalidated scripts w/o second thoughts (or even first thoughts actually) on their main machine, I’d say the “tech-aware” line is very very high…
But still, I fully share the sentiment that creators of an OS are perfectly capable of bypassing whatever there is running on top of it.