• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Apple drops controversial firewall-bypass feature on macOS

You are here: Home / General Cyber Security News / Apple drops controversial firewall-bypass feature on macOS

A mouse hovering over the Safari logo on a MacBook

Apple has eliminated a controversial aspect in its macOS running program that permitted much more than 50 of its have apps to absolutely bypass 3rd-party security instruments like firewalls and virtual private networks (VPNs).

The ContentFilterExclusionList, introduced in macOS 11 Large Sur, was flagged by the security community and developers late last year as becoming a potential security risk. This list’s existence in macOS meant traffic produced from Apple software this kind of as Maps and iCloud couldn’t be blocked by a socket filter firewall.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
F Secure Safe 2021

Protect yourself against all threads using F-Seure. F-Seure is one of the first security companies which has never been backed up by any governments. It provides you with an award-winning security plus an optimum privacy.

Get F-Secure Safe with 65% discount from a bitdefender official seller SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The developer of the Minor Snitch firewall tool, Norbert Heger, described this conduct as “a hole in the wall”.

Patrick Wardle, a security researcher with software business Jamf, even shown how it may be achievable for malware to abuse “excluded” applications to deliver web targeted visitors to bypass firewalls. 

These who at first sounded the alarm, such as Heger, Wardle and many others, have now welcomed Apple’s conclusion to eliminate ContentFilterExclusionList with the launch macOS 11.2 beta 2.

The exclusion checklist fist emerged as portion of Apple’s shift away from third-party kernel extensions, together with network kernel extensions (NKEs), which permitted builders to load code immediately into the macOS working technique. These NKEs, however, had been utilized by a variety of third-party security platforms, together with firewalls such as LuLu and Small Snitch.

To keep on to assistance these solutions on modern-day iterations of macOS, Apple launched the consumer-method Network Extension Framework (NEF), which developers could use as a substitute to retain macOS compatibility for their firewalls and VPNs.

Apple then exempted additional than 50 of its have programs and daemons from staying routed through the NEF by introducing the ContentFilterExclusionList. This meant 3rd-party firewalls that used this new framework weren’t ready to block website traffic from them.

“Many (rightfully) requested, “What very good is a firewall if it cannot block all traffic?”,” Wardle mentioned in a blog write-up. “Well, after plenty of lousy press and heaps of feedback/bug stories to Apple from builders these as myself, it seems wiser (a lot more security acutely aware) minds at Cupertino prevailed.”

“The ContentFilterExclusionList listing has been removed (in macOS 11.2 beta 2). Which suggests, (socket filter) firewalls such as LuLu can now comprehensively filter/block all network site visitors.”

Scientists have speculated that Apple excluded its possess applications from the oversight of 3rd-party firewalls in the identify of total security. For case in point, if excluded, these companies might keep on to get updates when all web website traffic is blocked.


Some elements of this post are sourced from:
www.itpro.co.uk

Previous Post: «Google Closes Fitbit Deal Despite Ongoing Legal Probes Google closes Fitbit deal despite ongoing legal probes

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Apple drops controversial firewall-bypass feature on macOS
  • Google closes Fitbit deal despite ongoing legal probes
  • Facebook Sues Devs of Alleged Data-Scraping Chrome Extensions
  • Researchers Disclose Undocumented Chinese Malware Used in Recent Attacks
  • 15 Jan 2021Automated “Classiscam” Operation Made $6.5m in 2020
  • Fujitsu: High Risk of #COVID19 Vaccine Disinformation Campaigns
  • With insured losses estimated at $90 billion, did cyber insurance firms dodge financial calamity?
  • Early-stage cybersecurity investment flowing, despite pandemic
  • CISA says multiple attacks on cloud services bypassed multifactor authentication
  • 2020 Saw 6% Rise in Number of CVEs Reported

Copyright © TheCyberSecurity.News, All Rights Reserved.