Live data from Hacker News

LuLu: An open-source macOS firewall that blocks unknown outgoing connections

objective-see.com

121–130 of 252 posts

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#121
post #18

Nowadays it's more important to control and restrict outgoing connections than incoming connections. Who would had thought of that 25 years ago.

The world is going to split into “cheap AI” that runs in the cloud and is free or heavily subsidized by selling your data and giving you biased functionality toward the AI provider and “expensive AI” that runs completely locally and has no or limited outbound connectivity and is solely biased toward the user desires. Hopefully this comes in open source as it will be hard to write and expensive to run on local hardware.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#122

Earlier quoted context omitted.

> as is convention for named options on the command line. Gosh, I really wish that people would follow a convention for named options on the command line. I don't even really care which one, as long as they were all consistent in picking one.

I've seen /, -, --, and +. Any other ones leap to mind? I wonder if there's a complete list somewhere.

option=value, option:value, option/value and even option\value (without dashes). Not joking.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#123
post #52

Unfortunately, this still has the key flaw that has plagued outbound firewalls since their invention: "Currently, LuLu only supports rules at the 'process level', meaning a process (or application) is either allowed to connect to the network or not. As is the case with other firewalls, this also means that if a legitimate (allowed) process is abused by malicious code to perform network actions, this will be allowed."…

also, there's nothing preventing a program from debugging a trusted process, and getting that process to perform the requests for the malicious program.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#124

Earlier quoted context omitted.

https://github.com/henrypp/simplewall > Simple tool to configure Windows Filtering Platform (WFP) So much better than anything else I tested. Easy to import/export rules (XML) and there's also portable mode and advanced options (that goes beyond the simple UI you can see in the image).

Thanks for the recommendation. Looks like a really good app. It recommends to disable the Windows firewall - which is understandable. But, then you start getting pestered by Windows to turn it back on. Do you turn off the Windows firewall or have them both turned on?

I disabled the firewall and alerts in the control panel.

This might be outdated but it's in the Control Panel or Action Center somewhere (Security and Maintenance area?). https://blogs.technet.microsoft.com/networking/2010/12/16/di...

I'm also using this simplewall option:

> Enable boot-time filters – Prevent data leak during system startup, even before "Base Filtering Engine" (BFE) service starts.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#125

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

Little Snitch has this with automatic profile switching: https://blog.obdev.at/automatic-profile-switching/ though you will have to build the list of rules yourself

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#126
post #57

Looks promising. I used to use Little Snitch, but last year they decided to charge for the new version, and I uninstalled it. Little Snitch was effective, but overly complex for the average user. I'm sure it's great for someone who configures networks on a regular basis, but as a Mac user, I just want to use my Mac. If I wanted to twiddle with security settings all day long, I'd still be on Windows. This looks like i…

That comment makes me chuckle. These days, I have close to zero faith in commercial software that is "free", assuming that the business model is selling my data. I happily paid for Little Snitch and was comforted by the fact that I was the customer.

>I happily paid for Little Snitch and was comforted by the fact that I was the customer.

I paid for it, too. But then the upgrades went from complimentary to paid, and I bailed.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#127

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

I know it's not the same thing, but I use TripMode on macOS for your last two points, which selectively blocks app access based on what network you're connected to.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#128

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

There used to be an application used by torrenters called PeerGuardian and then PeerBlock, which was basically just that. It was a curated list of IPs that were known to belong to domains at universities, companies, governments, etc. It probably had malicious domains in there as well.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#129
post #71

Is the author associated with CrowdStrike? I noticed he/she was using FancyBear

Why downvote a legit question on topic? The term FancyBear came from the cofounder of crowdstrike: Dmitri Alperovitch.

http://www.esquire.com/news-politics/a49902/the-russian-emig...

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#130

Earlier quoted context omitted.

oh dear, LittleSnitch wanted to charge money for creating a really handy tool, how terrible.

It’s the charge for upgrades that I don’t like. I bought it once, upgrades should be free. Or so significant that I want to pay.

Considering Apple's constant shifting of goalposts with macOS, what counts as "significant" in your book, even disregarding user-facing features? And how significant is the ~$50 they want for it?
Post reply on HN