| ▲ | ActorNightly 5 hours ago |
| Apple OS will bypass any user space firewall. You can verify this yourself. Get an old laptop to act as a wifi hotspot and forward traffic over usb ethernet adapter to your actual router. Then run tcpdump on the computer. You will see the multitude of phone-home traffic. |
|
| ▲ | throwaway27448 4 hours ago | parent | next [-] |
| Is there evidence of this anywhere on the internet? I couldn't find anything with ten minutes of searching, and I don't use little snitch, and I'm not going to put the effort in to remediate this just to figure out if this comment has weight. |
| |
| ▲ | agsnu 4 hours ago | parent [-] | | Probably referring to https://www.obdev.at/blog/a-hole-in-the-wall - as of 2020 > As it turned out, this behavior is on purpose. There’s an explicit whitelist that allows certain macOS services to bypass any third party firewalls and to communicate on the Internet without being even noticed by the user. A hole in the wall. Was remediated later, but shows there is precedent. | | |
|
|
| ▲ | arcanemachiner 4 hours ago | parent | prev | next [-] |
| Non-macOS user here. Does macOS not let you run things as root? |
| |
| ▲ | nhubbard 4 hours ago | parent [-] | | It does let you run things as root. | | |
| ▲ | VCFundedGenYer 4 hours ago | parent | next [-] | | Not exactly. What is "root" in macOS is more or less a power user role. Apple took away the true ability to operate as root a long time ago with System Integrity Protection which walls off the critical parts of the OS from the user entirely. Unfortunately, SIP also restricts basic system functions that are trivial in other OSes. Apple made this very difficult, and MS would have loved to do this in Vista had they not received the backlash that they did. | | |
| ▲ | frizlab 4 hours ago | parent [-] | | You can disable SIP if you want. You can run whatever you want on your machine. Disabling SIP is indeed a security risk… then again, so is running something as root. Having a Mac w/o SIP is no more a security risk than having a Linux w/o a r/o kernel AFAIK. | | |
| ▲ | asdff 35 minutes ago | parent [-] | | The way apple talks about SIP its like a miracle we survived at all pre SIP. Pretty sure I've had SIP disabled for years now when I got nagged for something or whatever and had to disable it. | | |
| ▲ | frizlab 6 minutes ago | parent [-] | | SIP is a good thing and prevents a lot of (usually PEBKAC) problems. It is also the direction where Linux is going (is now? or maybe they gave up? idk, it’s been a while since I heard about immutable distros). For tech-aware people, it is probably not necessary indeed.
However, given that now “tech-aware” people are running completely random and unvalidated scripts w/o second thoughts (or even first thoughts actually) on their main machine, I’d say the “tech-aware” line is very very high… |
|
|
| |
| ▲ | 4 hours ago | parent | prev [-] | | [deleted] |
|
|
|
| ▲ | wartywhoa23 4 hours ago | parent | prev [-] |
| Well, I block all connections to iCloud for every app (user and system) completely with Little Snitch, and the fact that it does indeed break some little features I can absolutely live without, indicates that it has at least some effect. But still, I fully share the sentiment that creators of an OS are perfectly capable of bypassing whatever there is running on top of it. |