Live data from Hacker News

LuLu: An open-source macOS firewall that blocks unknown outgoing connections

objective-see.com

61–70 of 252 posts

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#61
post #60

Earlier quoted context omitted.

So it is open source, but you're not free to do what you want with it.

Non-commercial clauses are explicitly prohibited by the OSD.

Link for the lazy: https://opensource.org/definition

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#63
post #55
post #52

Unfortunately, this still has the key flaw that has plagued outbound firewalls since their invention: "Currently, LuLu only supports rules at the 'process level', meaning a process (or application) is either allowed to connect to the network or not. As is the case with other firewalls, this also means that if a legitimate (allowed) process is abused by malicious code to perform network actions, this will be allowed."…

Combining process (source) and destination rule combos, the Little Snitch could be customized to "solve" this issue. Process A is allowed to talk to domains X, Y and Z. "Solve" not solve because, for me, setting up baseline rule sets was too intrusive to my workflow.

> Combining process (source) and destination rule combos, the Little Snitch could be customized to "solve" this issue. Process A is allowed to talk to domains X, Y and Z.

Ok, and what happens when I want to browse to a different site?

>for me, setting up baseline rule sets was too intrusive to my workflow

It seems like that would be true for anyone that wants to use their browser to go to more than a small number of websites.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#64
post #18

Nowadays it's more important to control and restrict outgoing connections than incoming connections. Who would had thought of that 25 years ago.

Give it another 25, and you will have to pay a premium for things which are stand-alone, disconnected from the net. Want a car which is not navigating using cloud AI? Only the rich can afford that...

I really have no problem with sharing my information openly in cases my presence has an obvious effect on those around me. Letting other cars within a certain radius know where I am seems a reasonable sharing of my information. I would go as far as sharing my intended destination so that some "cloud" some where can better plot my route to minimize traffic for me and others. That said, storing all that information for later analysis, which is possible given what I've shared, would be an unreasonable use of my data (unless it's done as part of some aggregate information). The problem of course is that once I share that information I lose control of how it is used later. If someone can devise a way for me to share my information while controlling how that information can be used later, it would go a long way to striking the right balance. I guess that's more or less "personal DRM" for our information.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#65
What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that.

I'd also like separate lists for

* "this wifi is public, be extra cautious"

* "this wifi is public, be nice and don't torrent, do backups, etc"

* "I'm on a metered connection (e.g. LTE), don't run torrents, backups, etc"

edit: for anyone looking for a monetizable idea: this post has 41, no 42, no 43 points in about an hour. Probably a good idea...

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#66
post #60

Earlier quoted context omitted.

So it is open source, but you're not free to do what you want with it.

Non-commercial clauses are explicitly prohibited by the OSD.

open-source != Open Source

open-source == source code is open

Open Source == licensed compliant with the OSI's OSD

right?

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#67

Looks promising. I used to use Little Snitch, but last year they decided to charge for the new version, and I uninstalled it. Little Snitch was effective, but overly complex for the average user. I'm sure it's great for someone who configures networks on a regular basis, but as a Mac user, I just want to use my Mac. If I wanted to twiddle with security settings all day long, I'd still be on Windows. This looks like i…

I paid for the old version. I like it.

I think they only charge for the new microphone / camera portions of the new version.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#68
post #18

Nowadays it's more important to control and restrict outgoing connections than incoming connections. Who would had thought of that 25 years ago.

it was thought of 25 years ago , I remember using a tool that monitored all outgoing traffic and I needed to approve any traffic that was not already authorized.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#69
post #20

For those on Windows, http://www.sphinx-soft.com/Vista/index.html does the same using the native firewall (so no 3rd party dependencies, services, or bloat) (though they've ~recently added paid licenses with more features to their basic offering). I only wish it were cleaner and simpler. I don't think the Windows Firewall API is too bad, I should add this to my bucket list of open source software to write that I'll m…

Thanks for the link. I'm curious how it compares to https://www.binisoft.org/wfc.php although this looks to be free I don't think it's open source. Not having much luck finding license info for it.

I have not used Simplewall but I am a paid customer of Binisoft WFC and do recommend it. WFC works great and is frequently upgraded, the developer is very responsive to his users.

It does have a crude ugly UI, so just don't expect it to look like Little Snitch (which I also endorse on MacOS) or Glasswire.

Post reply on HN