Headphone Safety, Big Sur, & Geek Challenges — Mac Geek Gab 854

Big Sur continues to mature…and it continues to have some pesky little issues, too. Never fear, your two favorite geeks are here to answer your questions and help solve your problems. Listen as John and Dave talk through Big Sur, Headphone Safety, and share some Geek Challenges of yours with the Mac Geek Gab family. Press play and enjoy learning at least…five new things!

Apple Apps No Longer Bypass macOS Big Sur Firewalls

In macOS Big Sur, Apple deprecated third-party kernel extensions including Network Kernel Extensions (NKEs). NKEs are used by apps like firewalls to monitor network traffic. Apple’s new user-mode Network Extension Framework had a side-effect: Apple’s own apps wouldn’t be routed through it and thus could bypass third-party firewalls. But now that has changed.

I of course also wondered if malware could abuse these “excluded” items to generate network traffic that could surreptitiously bypass any socket filter firewall.  Unfortunately the answer was yes! It was (unsurprisingly) trivial to find a way to abuse these items, and generate undetected network traffic.