Unwanted network connections.

To start I am hoping this post will be put in Apple Support Communities > Mac OS & System Software > El Capitan...


I am currently using a 13" Macbook Pro late 2014 RETINA display SSD hard drive with an i5 intel. However I have been using mac's for the past 10 or so years and I love them. I am starting this discussion for the simple yet complex questions involved with network activity. What ever happened to booting up your mac/system and you "the user" is the person who makes all of these outside connections to the internet. I use Little Snitch, along with iStats. It seems kind of weird to need an app to watch all of your network connections. I was always under the impression only Windows (especially windows 10) was the OS that kept and sent all of your data back to Microsoft. Simply put for the lay mac user we don't even know what the majority of these daemons are trying to connect to the web for. A quick example is gamed. I have researched and looked up all of the Game Kit Frameworks which support this protocol, in total I believe there are 16. I have looked at each and decided I don't use any of them so why does this daemon need to connect to the outside world automatically? So I decided I would not allow it to connect to the web. Unfortunately i have recently read El Capitan has "System Integrity Protection" which prevents even root from modifying system files. So in short what does this mean? Again as a lay mac user (i am not a programmer or computer engineer) why must certain items run even if I don't use them? Geo-location is another example, probably better than gamed. I am under the assumption after researching a little bit, the com.apple.geod.xpc protocol basically is a location service. Well what if I don't want my location to be documented constantly while using my mac? Why can't i just turn it off. I believe it is mainly used for Maps. I started this thread with the intention of maybe getting an answer with a list of protocols/daemons/connections which need to be made and why. It seems like everyday I am googling to see what one of these Apple services are and why I need to be allowing it to connect to the web. Recently I had an unauthorized ovh.net server attached to my netstats and it was only receiving data from my laptop. I am not sure if i caught a virus on a website or something, but it spooked me enough to wipe my SSD and do a clean re-install. For me this process isn't very difficult because i keep all of my photos and data backed up on external hard drives and i just wanted to make sure that the server which was connecting to me was gone, and took whatever little code that allowed it to connect was gone with it. In short I would really appreciate some replies with Apple services which try to connect upon startup but you do not need. I am trying to run a system with as little bloat as possible. I do not want to use iCloud but it almost seems impossible because i own an iPhone, Macbook, and other Apple products which all want to communicate (even though i wish they were just single entities). If I can please get some help with things I can get rid of without disrupting the integrity of my UNIX-like OS aka OS X El Capitan I would be very happy. I would also like to see some replies to see if anyone feels the same way I do.

Thanks

MacBook Pro (Retina, 13-inch, Mid 2014), OS X El Capitan (10.11.3)

Posted on Feb 1, 2016 8:30 AM

Reply
66 replies

Feb 9, 2016 3:43 PM in response to Drew Reece

Qradar was a joke. If you ever worked as a sec analyst for a decent sized co. maybe you have used it (almost certainly). It's proprietary and very expensive. But yes I did enjoy your post, thanks. Also Drew it is Apple's protocol... so it is their fault. I mean yes the dev's should have used HTTPS but a lot of these programs have been around for ages. However if you're blocking almost everything from your gateway you'll have no issues. Unfortunately we are in the MINORITY. This post is just to open peoples eyes and let them know about all of the connections being made with or without their consent. I hope your continue to follow the post. I am a bit useless now because i went out for happy hour after work. But I needed to reply.

Feb 18, 2016 8:08 AM in response to OregonRebel

AssetCacheLocator.xps- all kinds of weird stuff

ocspd - youtube- don't use

AppleIDAuth - even though icloud is off

nsurlsessiond - another icloud thing

IMTransferAgents (multiple) -- even though I've turned these off too, THEY KEEP TURNING BACK ON!


Help with the last PLEASE. How can i STOP my iPhone from communicating with my macbook pro.


oh yeah the FaceTime protocols too always running.

Feb 18, 2016 10:16 AM in response to GreenMamba

GreenMamba wrote:

AssetCacheLocator.xps- all kinds of weird stuff

Block it with Little Snitch, then try downloading a software update from the App Store or iTunes store - let us know if you can download anything.

It appears* to be part of the 'Apple caching service' that can simply save internet bandwidth if you have a Mac OS caching server. OS X and iOS will look for many services on the local network - it is part of what makes Apple devices 'just work' (most of the time 🙂).


http://help.apple.com/serverapp/mac/5.0/#/apd74DDE89F-08D2-4E0A-A5CD-155E345EFB8 3 (About Caching service)

From the Apple documentation:

Compare Caching service to Software Update service

… (2nd bullet point)

The Software Update server requires you to manually configure clients to only use a specific software update server; the caching server requires no client configuration. OS X and iOS devices automatically access the available caching server on the network they’re currently connected to, making it mobile-client friendly. For example, when a user is using an OS X or iOS device at work, the device uses the caching server at work. When the same user uses the same device at home, it automatically uses another caching server.

Automatic connections on the local network - nothing to worry about. Your devices will look for local cache servers and then go to the stores via the internet if one is not available. OS X & the iTunes store will periodically look for app updates - harmless.


GreenMamba wrote:

ocspd - youtube- don't use

You are wrong, this is a daemon for OCSP nothing to do with YouTube…

https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol


OCSPD updates certificates from the internet for use with secure (https) connections. It makes sure that your computer knows which certificates not to trust and which are valid, certificates can be revoked at any point in time (e.g. if they are compromised on the server).

You may actually be weakening your Mac's security by blocking OCSPD - your Mac may trust certificates that are in the hands of criminals. Using old certificates does open your Mac up to spoofing & man in the middle attacks.

You could turn off this process in 'Keychain Access, Certificates tab' preferences, if you do not value your security on the internet.


GreenMamba wrote:

nsurlsessiond - another icloud thing

Many people speculate* this is iCloud however Apple use a similar feature on iOS for all applications including ones made by third parties - it handles background downloads on iOS. I suspect it does similar things on Mac OS for any third party app, not just iCloud*.


GreenMamba wrote:

AppleIDAuth - even though icloud is off

IMTransferAgents (multiple) -- even though I've turned these off too, THEY KEEP TURNING BACK ON!

It seems like you still have not disabled all of iCloud on your iOS & OS X devices. Perhaps these are just local connections?


You may feel like I am picking on you but it is not my intention, I'm hoping that you can see that operating systems are a complex things. I'm willing to bet that you may not understand how every piece of a car works, however you probably allow yourself to be transported by one at speeds that are 'unnatural' for a human. Computers are no different, many peices working in lockstep doing things we don't understand. I doubt you would decide to disable parts of a vehicle based on similar suspicions. That would be reckless.



I truly understand the need to control your data but do you really think Apple would start a legal fight with the US government if they didn't care about your data privacy?

http://www.apple.com/customer-letter/

It doesn't add up.



* Apple do not document many OS processes, most of what you read outside of apple.com is speculation, amateur sleuthing or sometimes based on informed testing. Working out which one is accurate is half the battle.

Mar 2, 2016 4:02 PM in response to OregonRebel

Here's a link to another network-monitoring app. http://goo.gl/QpIayO

This is abandonware but still works, so download & use at will.


I installed it yesterday on OS X 10.11.3 and added it to my login items.

I think it works well in conjunction with Little Snitch, although its CPU usage runs high, keeping it at or near the top of the list in Activity Monitor.


Rubbernet provides a breakdown of per-app network usage, so you can quickly detect apps that phone home, connect to servers without your knowledge, or blame the app that's slowing down your network.



Macobserver article: http://goo.gl/ROLhQ2


"Rubbernet will show all of the application and services on your Mac that are using the network. Some of them are expected, such as Safari and Mail, but some of the other items listed may be ones you hadn’t thought about, such as Push Services or MobileMe. In the Summary view for each application that is found, you can see the name, status (active, inactive or idle) the user that owns the application, current download rate, current upload rate, total data in, total data out, and time of last activity. There is also a connections view, which will show the remote host, port, application, user, download rate, upload rate and last activity, so you can get very specific.

Clicking on a specific application will show the aforementioned connections items, but only for that application. You can also click on a user, and it will show the connection items that belong to that user. The preferences allow you to enable or disable IP address resolution."

Mar 2, 2016 5:40 PM in response to OregonRebel

OregonRebel wrote:


Here's a link to another network-monitoring app. http://goo.gl/QpIayO

This is abandonware but still works, so download & use at will.

That installer is bundling other junk.


  • Yahoo search engine hijack
  • Mackeeper
  • Various other junk apps


Are you sure it is not doing other malicious things? Installers have become a prevalent way to attack Macs, see the many threads here detailing adware & other junk that is bundled with apps that are no longer maintained or stored on dubious servers.


Does it even install the app you want to use, nothing appeared in /Applications after 'installing' (on a throwaway installation)?!



I'm not sure that running code that is found randomly on the internet is going to help anyones privacy. Apple are the least of your worries.

Mar 2, 2016 6:06 PM in response to Drew Reece

There is no installer, it's an app. Period.


Please provide proof of other junk inside Rubbernet.

EasyFind can't find any reference whatsoever to the words words yahoo or mackeeper inside the app, even when searching file contents and package contents.



It's running just fine on my computer although its daemon has disconnected from monitoring the network occasionally (it just happened again).

User uploaded file


Looks like it's not stable enough to stay connected all the time.

When it disconnects you just have to hit the Connect button to reconnect.

Mar 2, 2016 6:16 PM in response to Drew Reece

DON'T CLICK THE GREEN BUTTON!

Click above it on the app's name to download a torrent file (you'll need a torrent client).


Sorry, didn't think about explaining how to download it since I've used that site before and know how it works.


I made it easier, here's a link to download the app directly from a hosting site where I uploaded it. http://s000.tinyupload.com/?file_id=67652173436658543657

Mar 3, 2016 10:40 AM in response to GreenMamba

"The Sparkle.framework vulnerability gives "apps" which don't use HTTPS or the Mac protocol's a VERY easy way to run a MITM attack which than can allow you to run RCE. Try to always use "apps" you need to drag into your /Applications/ folder."


What has that got to do with the topic of this discussion, which is Unwanted network connections?


Rubbernet IS an app, I already said that - it has NO installer.

I don't know what the green button tries to give you because I don't use it.


People aren't going to stop using package installers like ALL of Adobe's apps just because of the Sparkle vulnerability (which has already been addressed in a lot of updated apps).

Mar 5, 2016 9:24 PM in response to Grant Bennet-Alder

An extraordinarily unhelpful response, Grant. Especially from what one assumes is an experienced user (Level 9).


The question -- how does one turn off unwanted and invisible processes that regularly reach out to the internet without specifically needing the access -- is a good question, and the concern is shared widely among Mac users.


I've owned Macs since 1985, and am increasingly frustrated with the OS, which sacrifices enormous control and privacy for the sake of convenience and marketing.


Is there an effective way to regain control of the Mac's interaction with the internet? I don't think so.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Unwanted network connections.

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.