{"id":112852,"date":"2020-11-16T12:11:57","date_gmt":"2020-11-16T09:11:57","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/apple-apps-on-big-sur-bypass-firewalls-and-vpns-this-is-terrible\/"},"modified":"2020-11-16T12:11:57","modified_gmt":"2020-11-16T09:11:57","slug":"apple-apps-on-big-sur-bypass-firewalls-and-vpns-this-is-terrible","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/apple-apps-on-big-sur-bypass-firewalls-and-vpns-this-is-terrible\/","title":{"rendered":"#Apple apps on Big Sur bypass firewalls and VPNs \u2014 this is terrible"},"content":{"rendered":"<p>&#8220;<strong>#<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le apps on Big Sur bypass firewalls and VPNs \u2014 this is terrible<\/strong>&#8221;<br \/>\n<img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/11\/header-image-Apple-apps-on-Big-Sur-bypass-firewalls-and-VPNs-796x417.png\" \/><\/p>\n<div>\n                                For all of Apple\u2019s talk of being privacy-first, often its marketing speak doesn\u2019t match up with what it\u2019s actually doing. And the latest example? Well, it\u2019s Apple apps on Big Sur bypassing firewalls and VPNs.<\/p>\n<p>I don\u2019t need to tell you just how worrying this is.<\/p>\n<p>The issue was first spotted in the macOS Big Sur beta by <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Twitter<\/a> user\u00a0<a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/mxswd\/status\/1318305284524183552\">@mxswd<\/a> all the way back in October. They had this to say:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Some Apple apps bypass some network extensions and VPN Apps. Maps for example can directly access the internet bypassing any NEFilterDataProvider or NEAppProxyProviders you have running ?<\/p>\n<p>\u2014 Maxwell (@mxswd) <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/mxswd\/status\/1318305284524183552?ref_src=twsrc%5Etfw\">October 19, 2020<\/a>\n<\/p><\/blockquote>\n<p>This was confirmed and expanded upon by <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/patrickwardle\">Patrick Wardle<\/a>, a security researcher at <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/www.jamf.com\/\">Jamf<\/a>.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">This is true ?<\/p>\n<p>Previously, a comprehensive macOS firewall could be implemented via a Network Kernel Extension (kext)<\/p>\n<p>Apple deprecated kexts, giving us Network Extensions\u2026.but apparently (many of) their apps \/ daemons bypass this filtering mechanism.<\/p>\n<p>Are we ok with this!? <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/t.co\/rYkDnuOgLJ\">https:\/\/t.co\/rYkDnuOgLJ<\/a><\/p>\n<p>\u2014 patrick wardle (@patrickwardle) <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/patrickwardle\/status\/1318437929497235457?ref_src=twsrc%5Etfw\">October 20, 2020<\/a>\n<\/p><\/blockquote>\n<p>Effectively, Wardle says that previous versions of macOS allowed a firewall or VPN to be set up using the\u00a0Network Kernel Extension. But this isn\u2019t the case in Big Sur.<\/p>\n<p>What Wardle found is that the Mac App Store on the latest macOS bypasses any firewall. For all intents and purposes, its traffic is invisible to firewalls. What\u2019s happening is that Apple apps on Big Sur are beginning to operate outside the user\u2019s control. Which is terrible <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>.<\/p>\n<p>This story was brought to light on <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/appleterm.com\/2020\/10\/20\/macos-big-sur-firewalls-and-vpns\/\/\">Apple Term<\/a>, but many assumed it would be fixed when Big Sur was released to the <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/general\/\" data-internallinksmanager029f6b8e52c=\"3\" title=\"General\" target=\"_blank\" rel=\"noopener\">general<\/a> public. This hasn\u2019t happened.<\/p>\n<p>The question you might be asking next is so what? What\u2019s the issue here?<\/p>\n<p>Well, aside from control over\u00a0<em>your own system<\/em>, Apple apps on Big Sur being able to bypass firewalls and VPNs is a huge privacy and security issue. Wardle showed on Twitter how easy it is for malware to exploit this gap:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">In Big Sur Apple decided to exempt many of its apps from being routed thru the frameworks they now require 3rd-party firewalls to use (LuLu, Little Snitch, etc.) ?<\/p>\n<p>Q: Could this be (ab)used by malware to also bypass such firewalls? ?<\/p>\n<p>A: Apparently yes, and trivially so ??? <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/t.co\/CCNcnGPFIB\">pic.twitter.com\/CCNcnGPFIB<\/a><\/p>\n<p>\u2014 patrick wardle (@patrickwardle) <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/patrickwardle\/status\/1327726496203476992?ref_src=twsrc%5Etfw\">November 14, 2020<\/a>\n<\/p><\/blockquote>\n<p>What this amounts to is that bad actors could exploit this hole in Apple apps on Big Sur to send out your personal data to remote servers. This should worry everyone.<\/p>\n<p>The big question though is\u00a0<em>why<\/em> the company\u2019s doing this. So far, it hasn\u2019t said why Apple apps on Big Sur are exempt from firewalls and VPNs, but there are some theories.<\/p>\n<p>One school of thought is that this makes it harder for users to pretend they\u2019re in different countries, meaning it can be stricter on licensing issues. Another is that Apple wants to keep its apps\u2019 data and traffic out of VPN servers.<\/p>\n<p>Whatever the reason, I severely doubt its good enough to excuse Apple\u2019s actions here.<\/p>\n<p>If you want to understand further what this sort of activity does, I\u2019d recommend you go and read <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/sneak.berlin\/20201112\/your-computer-isnt-yours\/\">this piece from Jeffrey Paul about why your computer isn\u2019t yours<\/a>. It\u2019s a sobering look at the world we\u2019re living in, where<\/p>\n<p>So much for Apple being privacy-first, hey?<\/p>\n<p><i>For more gear, gadget, and hardware news and reviews, follow Plugged on<br \/>\n            <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/twitter.com\/plugged\">Twitter<\/a> and<br \/>\n            <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/flipboard.com\/@thenextweb\/plugged-54nihknvy\">Flipboard<\/a>.<br \/>\n            <\/i><\/p>\n<p class=\"c-post-pubDate\">\n                                    Published November 16, 2020 \u2014 09:11 UTC\n                                <\/p>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script data-src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js#xfbml=1&amp;appId=378011798897423&amp;version=v2.6\" id=\"socialSrcFacebook\" type=\"text\/template\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener noreferrer\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/plugged\/2020\/11\/16\/apple-apps-on-big-sur-bypass-firewalls-vpns-analysis-macos\/\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Apple apps on Big Sur bypass firewalls and VPNs \u2014 this is terrible&#8221; For all of Apple\u2019s talk of being privacy-first, often its marketing speak doesn\u2019t match up with what it\u2019s actually doing. And the latest example? Well, it\u2019s Apple apps on Big Sur bypassing firewalls and VPNs. I don\u2019t need to tell you just&#8230;<\/p>\n","protected":false},"author":1,"featured_media":112853,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/img-cdn.tnwcdn.com\/image\/plugged?filter_last=1&fit=1280,640&url=https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/11\/header-image-Apple-apps-on-Big-Sur-bypass-firewalls-and-VPNs.png&signature=7451cf28fe169e250573be8de9f20c26","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-112852","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/112852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=112852"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/112852\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/112853"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=112852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=112852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=112852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}