Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Whitelist : xp.apple.com - this is used for apple device restore #562

Closed
1 of 4 tasks
zeezeepiggy opened this issue Jun 14, 2022 · 13 comments
Closed
1 of 4 tasks

Whitelist : xp.apple.com - this is used for apple device restore #562

zeezeepiggy opened this issue Jun 14, 2022 · 13 comments
Labels
declined Won't be worked on

Comments

@zeezeepiggy
Copy link


Submit Form

Get your issue resolved quickly! Fill in the form accurately.

Lists in use:

  • mini
  • Lite
  • Pro
  • Xtra

Client:
Itunes, MacOS, nextdns


Domains:

xp.apple.com


Details:

xp.apple.com Is used for device updates and OS restore of macos and ios.

this is not a telemetry, but a common checker of the device.

i was restoring my personal MacBook pro and it keeps on failing with unable to connect to apple server. I then found the culprit that xp.apple.com is being blocked by 1host Pro. I change the blocklist and white list it. The restore went fine.

sorry. no screentshot of the failed macbook….

+++++

to verify this, i went to check my companies firewall allow list document ( my company uses apple products and we manages some blocklist as well), then wiki states the below:

XP.APPLE.COM - Allowed for device Restore and Update. Brick Device Possible if this is Blocked.
*SMOOT.APPLE.COM - Needs to be allowed. design team complains Spotlight Search not working.

Details verified with Apple Business and Tech Support. (IM8908765 and IM4326578)

both of these are blocked by 1host Pro. Can we unblock these? I cannot always use my companies DNS/VPN since they monitor it.

Thank you for supporting 1Hosts.

It’s people like you who make these lists great! ❤
@hagezi
Copy link
Contributor

hagezi commented Jun 14, 2022

I had suspected that this would lead to problems, the domains are not for nothing on the Apple support list of domains to be released in corporate networks. But I could not prove it.
See: #536

You won't find them on common blocklists either.

@badmojr
Copy link
Owner

badmojr commented Jun 16, 2022

i was restoring my personal MacBook pro and it keeps on failing with unable to connect to apple server.

That doesn't scare you a bit?

@badmojr badmojr added discussion .💬 Needs broader input labels Jun 16, 2022
@zeezeepiggy
Copy link
Author

i was restoring my personal MacBook pro and it keeps on failing with unable to connect to apple server.

That doesn't scare you a bit?

Initially It did, but i believe every error has a solution. So i did some normal debugging until i found the solution.

Also, I now work in tech and my new team also fixes issues with mac and other apple device issues. We work with the Apple Business Tech Team when we encounter issues. We originally had a very aggressive firewall in the company, but some of them we whitelisted. Hope it makes sense.

@zeezeepiggy
Copy link
Author

Also, should we add this in 1host Extra instead?

@badmojr
Copy link
Owner

badmojr commented Jun 17, 2022

Also, should we add this in 1host Extra instead?

I'm afraid not! We currently don't have this feature, as can be seen here.

@zeezeepiggy
Copy link
Author

zeezeepiggy commented Jun 17, 2022

@badmojr i will let you decide if you want to whitelist this or not in the Pro blocklist.

For the time being, I will allowlist this domain in nextdns and also the *smooth.apple.com… to prevent device bricking.

I really want yo share the documents from my Company about the apple whitlisted domains and their reason plus their IM number but I can’t as its confidential and i dont want to get into trouble. 😆✌🏻✌🏻

Please close if required.

@badmojr badmojr added declined Won't be worked on and removed .💬 Needs broader input discussion labels Jun 17, 2022
@badmojr
Copy link
Owner

badmojr commented Jun 17, 2022

OK! Closing...

@badmojr badmojr closed this as not planned Won't fix, can't repro, duplicate, stale Jun 17, 2022
@yokoffing
Copy link

@badmojr

XP.APPLE.COM - Allowed for device Restore and Update. Brick Device Possible if this is Blocked.

https://oisd.nl/excludes.php?w=xp.apple.com - Required for installing, restoring, and updating macOS, iOS, iPadOS, watchOS, and tvOS. See https://support.apple.com/en-us/HT210060

*SMOOT.APPLE.COM - Needs to be allowed. design team complains Spotlight Search not working.

https://oisd.nl/excludes.php?w=smoot.apple.com
specifically: https://oisd.nl/excludes.php?w=api.smoot.apple.com

@badmojr
Copy link
Owner

badmojr commented Nov 14, 2022

@yokoffing , @zeezeepiggy , @hagezi

https://youtu.be/8JxvH80Rrcw

@hagezi
Copy link
Contributor

hagezi commented Nov 14, 2022

@badmojr Yes, thank you, I was completely wrong.
https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558

@yokoffing
Copy link

yokoffing commented Nov 14, 2022

I hope Apple disables this in the future. I have a lot of anti-tracking measures in place, up to breaking functionality of a few things.

However, all the issues we've documented historically still occur (AFAIK) when blocking xp and smoot. The Pro list description says it may cause "some minimal breakages", and I consider these a few rings above small breakage. And unlike something like graph.facebook.com, the issues impact users on the operating system level, not an optional social media site.

Update: nextdns/metadata#1132

@hagezi
Copy link
Contributor

hagezi commented Nov 30, 2022

@badmojr
I have found something that does not work by blocking xp.apple.com. 4 out of 4 Apple Watches in my household would not update. The behavior is as follows:
The Watch shows that an update is necessary, if you start it it hangs at "search for update". I waited 10 minutes before cancelling the process. I tried it on every Watch.
Unblocking xp.apple.com fixed the problem.
I have removed xp.apple.com from my blocklists.

ping @AdguardTeam @jellizaveta @Alex-302

Alex-302 added a commit to AdguardTeam/AdguardFilters that referenced this issue Nov 30, 2022
@Alex-302
Copy link

@hagezi Thanks, checked and removed.

@Quorum75 Quorum75 mentioned this issue Dec 18, 2022
4 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
declined Won't be worked on
Projects
None yet
Development

No branches or pull requests

5 participants