GLOBAL RESEARCH SYNDICATE
No Result
View All Result
  • Login
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
No Result
View All Result
globalresearchsyndicate
No Result
View All Result
Home Data Collection

MacOS Big Sur(veillance) bypasses Firewall/VPN to tell Apple what programs you run on your computer

globalresearchsyndicate by globalresearchsyndicate
November 21, 2020
in Data Collection
0
MacOS Big Sur(veillance) bypasses Firewall/VPN to tell Apple what programs you run on your computer
0
SHARES
26
VIEWS
Share on FacebookShare on Twitter

MacOS Big Sur(veillance) bypasses Firewall_VPN to tell Apple what programs you run on your computer

Some default Apple apps on MacOS Big Sur bypass any VPN or firewall rules set by the user to send information like what programs you run back to Apple. Namely, the Apple App store and 50 other Apple apps are allowed to bypass user based internet routing rules which means Apple could know your real IP address even when you try to get behind a VPN on MacOS Big Sur. Additionally, this type of exemption can be exploited by malware.

In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) 🧐

Q: Could this be (ab)used by malware to also bypass such firewalls? 🤔

A: Apparently yes, and trivially so 😬😱😭 pic.twitter.com/CCNcnGPFIB

— patrick wardle (@patrickwardle) November 14, 2020

This VPN ignoring behavior was first discovered in MacOS Big Sur’s beta back in October; however, now that Big Sur has exited beta, the privacy ignoring “feature” still remains. One of Apple’s programs that is allowed to bypass VPN is cause for major privacy concerns. The program, called Gatekeeper, checks the certificate of any program run on your computer along with a timestamp and your IP address with Apple – which is enough data to start building a profile on what programs you use and from where.

Apple denies spying with GateKeeper and Big Sur

On Apple’s end, they explained Gatekeeper with an emergency release of a support doc this week that detailed the security measure. Additionally, Apple has stated that they will stop storing IP addresses with these authentication requests. Some argue that Apple just checks the program’s developer ID certificate for authenticity, and there is no stored hash of the program’s code for Apple to use to compile lists of programs used by individual Apple customers. Even with the existing system, Gatekeeper essentially creates a log of programs used by Apple users sorted by IP address.

An algorithm to guess with overwhelming probability which app someone is using when you observe a Mozilla cert OCSP request from a Mac:

Step 1: guess Firefox.
Step 2: there is no step 2.

— Matthew Green (@matthew_d_green) November 15, 2020

Apple of course denies that this information is used in that way. They stated:

“Gatekeeper performs online checks to verify if an app contains known malware and whether the developer’s signing certificate is revoked. […] We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices.”

It doesn’t matter if they did or not, the fact that the information is there means that it’s available for a government agency to come in and use. Additionally, the very existence of this type of privacy invading check opens up functionality issues which were recently highlighted.

Besides privacy concerns, Gatekeeper even led to usability downtime on Macs around the world

A recent spat of downtime for Apple servers also revealed another weak point with this Gatekeeper model.

Hey Apple users:

If you’re now experiencing hangs launching apps on the Mac, I figured out the problem using Little Snitch.

It’s trustd connecting to https://t.co/FzIGwbGRan

Denying that connection fixes it, because OCSP is a soft failure.

(Disconnect internet also fixes.) pic.twitter.com/w9YciFltrb

— Jeff Johnson (@lapcatsoftware) November 12, 2020

Namely, Mac users were unable to execute code or open programs because they would fail the OCSP check with Apple servers. Of course, it is possible to set up a Macbook completely offline and avoid this type of phoning home activity; however, that’s not how most people want to use their Apple devices. It’s important to note that Apple’s new M1 powered laptops won’t be able to run anything besides MacOS Big Sur. Apple has promised to make this Gatekeeper function better for users by adding encryption as well as a way to opt out.

It’s clear that this is Apple’s hamfisted way to try and salvage the not so true claim that “Macs can’t get viruses.” The truth is much more nuanced than that: Mac devices can get malware, there are always going to be more zero-days found, etc. Apple seems to be doubling down on this specific anti-privacy approach to stop malware – and that deserves all the reproach I can muster.

VPN Service

Related Posts

How Machine Learning has impacted Consumer Behaviour and Analysis
Consumer Research

How Machine Learning has impacted Consumer Behaviour and Analysis

January 4, 2024
Market Research The Ultimate Weapon for Business Success
Consumer Research

Market Research: The Ultimate Weapon for Business Success

June 22, 2023
Unveiling the Hidden Power of Market Research A Game Changer
Consumer Research

Unveiling the Hidden Power of Market Research: A Game Changer

June 2, 2023
7 Secrets of Market Research Gurus That Will Blow Your Mind
Consumer Research

7 Secrets of Market Research Gurus That Will Blow Your Mind

May 8, 2023
The Shocking Truth About Market Research Revealed!
Consumer Research

The Shocking Truth About Market Research: Revealed!

April 25, 2023
market research, primary research, secondary research, market research trends, market research news,
Consumer Research

Quantitative vs. Qualitative Research. How to choose the Right Research Method for Your Business Needs

March 14, 2023
Next Post
Immunity Boosting Foods Market Worth $25.21 Billion by 2026: Exclusive Report by Brand Essence Market Research

Immunity Boosting Foods Market Worth $25.21 Billion by 2026: Exclusive Report by Brand Essence Market Research

Categories

  • Consumer Research
  • Data Analysis
  • Data Collection
  • Industry Research
  • Latest News
  • Market Insights
  • Marketing Research
  • Survey Research
  • Uncategorized

Recent Posts

  • Ipsos Revolutionizes the Global Market Research Landscape
  • How Machine Learning has impacted Consumer Behaviour and Analysis
  • Market Research: The Ultimate Weapon for Business Success
  • Privacy Policy
  • Terms of Use
  • Antispam
  • DMCA

Copyright © 2024 Globalresearchsyndicate.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights

Copyright © 2024 Globalresearchsyndicate.com