Skip to content
HN On Hacker News ↗

Passive FTP Enabled on MacBook After Apple Store Reset and Other Observations

▲ 6 points • 9 comments • by cududa • 5d ago • HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is human-written.

0 %

AI likelihood · overall

Human
100% human-written 0% AI-generated
SEGMENTS · HUMAN 1 of 1
SEGMENTS · AI 0 of 1
WORD COUNT 1,599
PEAK AI % 0% · §1
Analyzed
Oct 4
backend: pangram/v3.3
Segments scanned
1 windows
avg 1599 words each
Distribution
100 / 0%
human / AI fraction
Verdict
Human
Pangram v3.3

Article text · 1,599 words · 1 segments analyzed

Human AI-generated
§1 Human · 0%

Examples of concerning Network and UI override settings on a brand new MacBook Neo that just underwent an Apple Store Device Firmware Update device wipe12 min readJust now--Cause For Reasonable ConcernMy last post covered my most recent observations as I work towards a clean and secured iCloud + set of Apple devices. This post will give some examples of what I mean when I say “odd behaviors” and a partial timeline of events.These are observations from a freshly wiped MacBook Neo that had an in-store DFU (Device Firmware Update) performed Friday October 2nd. The device is in Lockdown Mode, has no iCloud account attached to it, nor any third-party applications installed.System Configuration PLISTs — YikesDiving in… When I run sudo plutil -p /Library/Preferences/SystemConfiguration/preferences.plist I get some concerning results, including an indication there’s a constant FTP stream associated with my connection:Specifies en0 as WiFi. Includes a series of DNS, IPv4, IPv6, Proxy, FTP, SMB, and purported “User Defined” changes.Unfortunately, Apple’s documentation is so sparse I can’t tell what is supposed to be here or not.What I definitely know is not supposed to be here: FTPPassive set to true.Press enter or click to view image in full size“the client initiates both the command channel and the data channel, allowing connections to pass through client-side firewalls” — no thank you.Second, I really feel deeply these Proxy settings are likely not factory installed defaults, but again, Apple publishes nothing on this so on this I’ll begrudgingly accept they populate this field by default¹.Here’s another one.en0 makes a return but this time saying JoinMode is Automatic. The last image demonstrated en0 is our WiFi. I have Lockdown Mode turned on, which is supposed to prevent WiFi from auto-connectingI’m not in any way comfortable accepting that “JoinMode” => “Automatic” is benign if I’m in a feature called “Lockdown Mode”.The Apple Store Diagnostic iPhone/iPads show my devices as not being in enrolled in any Mobile Device Management (MDM) or Apple Business Manager (ABM) Servers.macOS Firewall UncertaintyLet’s take a look at my post-Apple Store DFU macOS Firewall Settings… First, all these entries — they don’t seem normal but all the LLM’s and their tenuous sources assure me these entries are default… Note that I manually set these entries to Block. Now let’s try interacting:Press enter or click to view image in full sizeI’m pretty sure pressing Ok isn’t supposed to undo the changes you make to the Firewall settingsEvery time I close the window the settings reset back to allowing any “signed” local software to accept any incoming connections. It’s entirely possible for there to be self-signed applications installed without my knowledge, if something is able to apply the above described changes.Searching Google or interacting with its AI modality shows various Apple Community Notes I have some concerns about². At one point, it even actively networking security advice that I can’t actually find a documented answer for. I installed Apple Intelligence on my iPhone to ask the same question — as, from what I understand, the base model is Gemini:Press enter or click to view image in full sizePress enter or click to view image in full sizeThis Reddit thread from 2025 shows a number of people passionately arguing their macOS Firewall as On or Off by default:Temporary Peace of MindWhile writing these posts I’ve used:sudo networksetup -setnetworkserviceenabled “Wi-Fi” off to get a bit of comfort of privacy to work, given the above documented issues … which results in the following This Connection Is Not Secure in Safari:Press enter or click to view image in full sizeThis Connection Is Not Secure displays when setnetworkserviceenabled turns off Wi-Fi but not when the Wi-Fi is toggled off.When I bring my WiFi back up (using the above command, swapping off for on) my iPhone in Hotspot mode will not show up as an available macOS WiFi network (I toggle all the iPhone cellular, wifi, hotspot and macOS WiFi ones on and off) and I have to manually enter the SSID and password⁴.Bonus GotchaBonus from a MacBook Pro in my home I suspect to be infected⁵:Press enter or click to view image in full sizeIt’s easy to miss, but at the 3 second mark when I click the Details dropdown to collapse Details at about the 2-second mark, the drop-downs switch from “Never Allow” to “Always Allow”.Using The Past to Contextualize The PresentI’ve been thinking a lot lately about the development of Windows Vista’s User Account Control (UAC — the annoying popup with a dark overlay that asked you to confirm security changes) alongside the introduction of the desktop compositor, or Desktop Window Manager (DWM— the thing that let you have transparent/blurred graphical interfaces like the glass/”Aero” taskbar and glass titlebars and borders — think the “frame” around the window to fun visuals like Aero Peek, hovering over a taskbar icon to show the Windows you have open).A big concern at the time was the real rising risk of “pixel overwrite attacks”, where an attacker perfectly positioned their UI atop the “secure” input. The user would type into the intercepted input, the attacker would pass the input to the real application so the user never was any the wiser.I’m not well-versed in macOS internals and woefully out of date at Windows. But I still can put together fundamentals… Let’s take a look at defaults read com.apple.systemuiserver:Press enter or click to view image in full sizedefaults read com.apple.systemuiserver shows __NSEnableTSMDocumentWindowLevelIf anyone has other commands to try in this vein, I’m all ears. There is very little that Google turns up for NSEnableTSMDocumentWindowLevel. What we can say:It seems to be an internal Apple API that allows overlaying a window atop all other windows to collect input. Google AI summarized it as: “an internal, legacy Apple configuration key used to control how a window’s layer hierarchy interacts with the Text Services Manager (TSM) in macOS”One result includes this GitHub Issue in simplified Chinese, in a repo that purports to clean stubborn spyware: https://github.com/tw93/Mole/issues/1000A post from 2010 that comes up in searches for NSEnableTSMDocumentWindowLevel that discusses stealing plist content: https://www.macscripter.net/t/configure-a-new-account-with-applescript-well-partly/59601I’ll leave the Windows Vista UAC/DWM history and investigation into com.apple.systemuiserver for a future post. If you have any genuine insights here, please reach out!Abridged TimelineA brief timeline of the most recent round of oddities⁶.Saturday, September 19th: Put my iPhone 15 Pro in Lockdown mode after noticing odd screen flashing while looking at sensitive materials. My iCloud account had Advanced Data Protection and other various security controls already turned on.Sunday, September 20th: My iPhone displays it’s first device-wide overlay loudly announcing an expired SSL certificate from May 29, 2025, while my AT&T BGW320–500 (Humax) is on and the fiberoptic PON is off.Thursday, September 24th: I turn off my AT&T Fiberoptic equipment and go iPhone only afterSaturday, September 26th: iPhone 15 Pro in permanent state of This Connection Is Not Secure following deletion of eSIM while in Lockdown Mode.Sunday, September 27th: Purchase new iPhone 18 Pro, new provider (AT&T), new phone number, new iCloud account. iCloud account setup in Apple Store. AT&T Line was added to an existing account at a nearby Authorized Retailer. I’ll note I found it a bit odd the retailer used Spectrum Wi-Fi for their own operations.Thursday Morning, October 1st: I finally bite the bullet and bought a MacBook Neo so I can get back to work. I set it up at home using my iPhone 18 Pro + it’s iCloud account and pretty quickly see 4 UTM tunnels turn into 8.Thursday Afternoon, October 1st: Head to an AT&T corporate store to get a new eSIM QR code instead of reactivating my phone there on their Wi-Fi/around other devices.Thursday Evening, October 1st: Head to the Apple Store where an incredibly helpful and compassionate manager treats my issue with respect and notes with curiosity he experiences one of the symptoms on his home computer. We proceed to perform a DFU on the iPhone 18 Pro, while he happily grabs a USB-C > Ethernet adapter so I can activate the iPhone with the QR code on their network.He also suggests I can come in the store to use their phone and Wi-Fi to talk to Apple Support the following day so they can run diagnostics on my iPhone while I talk to them.Friday, October 2nd: I come into the Apple Store with my notes all prepared and ready to talk to Apple Support and hopefully escalate the issue to engineering. We hit an undocumented issue where Lockdown Mode prevents uploading files to Apple’s upload portal⁶. Apple Store employees also see that my iCloud 6-digit verification codes between the Neo and 18 Pro (on their Wi-Fi) showing as invalid.Apple Support ends with directing me to the Security Program link, which doesn’t really put my devices in a usable state. They offer to help me wipe them, but I’d much rather Apple’s engineers are aware of this issue and can pull the exact logs/configurations that have lead to this state.Apple Store manager performs a DFU of the MacBook Neo which had been claiming to be up to date with macOS 26.6 — in fact it still says it’s logged into my account, we update to macOS 27.I want to clarify in no way do I blame the Apple Store employees for the presence of these Biome Proactive Harvesting containers. The initial post was an incredulity at Lockdown Mode without iCloud, Siri, or Apple Intelligence setup to include these invasive features.SummarizingHopefully this post helps demonstrate that we face an ecosystem devoid of reliable documentation and are rapidly ceding authoritative decisions to opaque models. Models that still will cite downright inaccurate and harmful security related advice when they should