news.volyx.in

Warning: DNS encryption in Little Snitch 6.1 may occasionally fail (obdev.at)

535 points by HelenePhisher · 690 days ago · 206 comments on HN

Article summary

The article discusses a bug in macOS that causes some DNS requests to bypass the installed DNS proxy and be sent unencrypted, affecting the DNS encryption feature in Little Snitch 6.1. The issue has been reported to Apple and was later found to be specific to Little Snitch 6.1, with a fix provided in version 6.1.1. The bug allows some DNS lookups to be visible in unencrypted form, potentially compromising user privacy. The issue is not unique to Little Snitch and may affect other DNS proxies.

Main themes

  • DNS encryption
  • macOS bugs
  • Little Snitch
  • network security
  • user privacy
  • software development

What commenters say

  • The bug in macOS that bypasses the DNS proxy is a significant issue that compromises user privacy and should be fixed by Apple.
  • The problem is not unique to Little Snitch and may affect other DNS proxies, highlighting a broader issue with macOS.
  • Some commenters argue that Apple's decision to deprecate certain network APIs and restrict third-party developer access is a contributing factor to the issue.
  • Others believe that applications should not be allowed to resolve DNS outside of user settings, and that blocking socket access could help prevent shady behavior.
  • There is disagreement over whether blocking socket access would be beneficial or would break legitimate applications that use other protocols.
  • Some commenters suggest that a more transparent and user-controlled firewall, like Little Snitch or Zonealarm, could help mitigate these issues and provide better user control over network traffic.
  • The issue highlights the challenges of testing and ensuring compatibility with older versions of macOS, and the need for better support from Apple for developers.