TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

MacOS sometimes leaks traffic after system updates

402 pointsby dulvui7 months ago

7 comments

thisislife27 months ago
&gt; In this scenario the macOS firewall does not seem to function correctly and is disregarding firewall rules ... Some examples of apps that do this are Apple’s own apps and services since macOS 14.6, up until a recent 15.1 beta.<p>This is not new - every time I update macOS, some of the system settings are changed to default including some in the firewall. And I have to painstakingly go through all of it and change it. Also, the few times I&#x27;ve reinstalled or updated macOS, I&#x27;ve always noticed that it takes longer for the installation if your system has access to the internet - so now I&#x27;ve made it a practice to switch of the router while installing or updating macOS or ios. (With all the AI bullshit being integrated everywhere in Windows, macOS and Android etc., I expect this kind of &quot;offloading&quot; of personal data, and downloading of data, to &#x2F; from AI servers to keep increasing, especially during updates, to &quot;prepare&quot; for the new AI features in the newer OS updates. No internet means the installer is forced to skip it for later, saving you some valuable time, and hopefully you get to change the default setting before it starts up again. Whatever the claims of AI processing done on the Mac or iDevices itself, some &quot;offloading&quot; to their servers, will still happen, especially if the default settings - which you can change only after the OS is installed - also enables analytics and data collection.)<p>(More here <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26418809">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26418809</a> and on this thread - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26303946">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=26303946</a> ).
评论 #41858347 未加载
评论 #41858894 未加载
评论 #41858667 未加载
评论 #41859069 未加载
评论 #41860418 未加载
chatmasta7 months ago
If you want leak-proof VPN, you need to implement it outside of your device, at the router level. This is true for any device but Apple devices in particular.<p>I highly recommended sniffing the traffic on the wire and piping it through wireshark. You can do this with a router, or a passive Ethernet tap. You’ll see a bunch of packets going to places other than your VPN entrypoint. If you use a router, you can check your mobile for leaks too. (Did you know if you have WiFi calling enabled, then your phone makes a TCP connection to a sensor server controlled by your ISP every 30 seconds? So if you’ve got T-Mobile and you’re abroad, not even using it as your default SIM, they’ll get a nice log of every exit IP you use.)<p>Apple’s seeming embrace of support for VPN and network filtering extensions is a red herring, because they’ll happily disable it for their own traffic.<p>On iOS, the App Store will skip any VPN, and similarly Apple will even block you from downloading updates if you’re on a VPN. I only realized this when I used my wireless router with VPN on it and updates failed to download.<p>On Mac, there are a bunch of issues, especially on first boot. It seems like the Mac will refuse to establish the VPN until it can make one connection outside of it. I encounter this when my computer wakes from sleep and the on-demand wireguard tunnel (using Cloudflare Warp) fails to send packets. I unplug my Ethernet, disable always-on, wait 30 seconds (for some timeout?), re-enable always-on, and then plug in the Ethernet and in connects. But I’m not actually sure this isn’t leaking, I need to investigate more.
mgoetzke7 months ago
it also leaks the audio of tabs before logging in.<p>Even though I had disabled all &#x27;restore&#x27; applications features, macos sometimes decides to &#x27;start&#x27; browsers BEFORE logging in after a restart AND those start auto-playing audio from whatever was paused before the reboot (or many days before).<p>Since then I went rather deep disabling that feature, but I never trusted it.
评论 #41857362 未加载
评论 #41857258 未加载
评论 #41857411 未加载
评论 #41857615 未加载
评论 #41857667 未加载
评论 #41857946 未加载
评论 #41857358 未加载
nubinetwork7 months ago
The article has today&#x27;s date on it, but I could swear I read this exact same article a month ago...
评论 #41859465 未加载
评论 #41861248 未加载
banku_brougham7 months ago
I&#x27;ve heard NixOS is good, but I guess I still need a GUI os because of browser and some apps I use regularly. I would love to get out of the macOS world, its going to a bad place. Seems like I&#x27;ve configured my whole digital life around apple.
评论 #41866557 未加载
akira25017 months ago
&gt; Unfortunately apps are not required to respect the routing table<p>Insane. Why even have one or expose it to the user if it&#x27;s just suggestive fiction?<p>Vendors really need to stop privileging themselves on users machines.
评论 #41888184 未加载
handsclean7 months ago
The first boot after a macOS system update has long been bugged out. It launches a bunch of apps you didn’t even have open before updating, seems to be the 5-10 most recent apps you quit. Yes they were fully quit, yes I have the “resume” setting off. It also doesn’t do a resume, it launches them, i.e. tells them to create new windows, and it launches them before it finishes mounting disks, resulting in every update being followed by all my most used apps appearing out of nowhere and telling me all my config and data is gone. It doesn’t really matter, you just reboot again and you’re good, it’s just careless and makes the OS feel unstable. Maybe the firewall thing is unrelated, maybe it finally forces Apple to fix the bug, we’ll see.
评论 #41857905 未加载
评论 #41858784 未加载