Live data from Hacker News

LuLu: An open-source macOS firewall that blocks unknown outgoing connections

objective-see.com

221–230 of 252 posts

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#221
post #57

Earlier quoted context omitted.

That comment makes me chuckle. These days, I have close to zero faith in commercial software that is "free", assuming that the business model is selling my data. I happily paid for Little Snitch and was comforted by the fact that I was the customer.

>I happily paid for Little Snitch and was comforted by the fact that I was the customer. I paid for it, too. But then the upgrades went from complimentary to paid, and I bailed.

That is the traditional business model of software

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#222
post #200

Earlier quoted context omitted.

I've always been hesitant to use DNS to block ads because it's difficult to turn off for non techies. Did the pi hole cause any issues in your experience?

Vanishingly few. Occasionally, I'm browsing the web and hit a text link that takes me to the browser's "I can't find this site" default screen. This usually happens with sponsored links that are not served from ad networks yet link to known ad sites.

My wife frequently complains about sponsored Google searches not resolving. She doesn't want to use an in-browser adblock, so the links will still appear, but aren't usable. Also, many redirecting analytics services from emails get blocked.

Personally, I don't find these to be breaking issues for my use. My only issue is that the PiHole interface's administrative features are authenticated via the PiHole's service user account password. This is the Ubuntu user password for the user the service runs under when installed on Raspbian or whatever. There's no secondary credential store. There isn't even a list of users. To log in, you enter the user's password. If there was a way to assign credentials to network users and allow them to whitelist/blacklist entries and audit that, it could easily be much more non-technical user friendly.

One final half complaint. If a link is direct to a blocked site that is served over ssl, you won't get the nice "This site has been blocked" page. It will just show the standard Chrome/Safari/Firefox "could not connect" error. As a technical user, this is normal and makes sense. For others, it makes "the internet" appear "broken". Obviously this isn't something a PiHole can fix on it's own, and I don't expect it to. It's a slippery slope to add a trusted root or intermediary cert to each of my network devices and allow a random box on my network to dynamically "poison" my DNS and serve fraudulent dynamically generated site certificates just to show me an informational page to allowing a random box on my network proxy and DPI my SSL traffic. It's not something I'm comfortable with maintaining.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#223
post #103

Earlier quoted context omitted.

I would pay for such a service as well. In addition to that, I would love if this service would allow companies like Apple and Google to maintains their own lists of IP's and update them regularly, so you can be 100% sure that an IP belongs to them.

Is that not somehow auto-discoverable using DNS trickery?

Not entirely. From what I understand, these outbound firewalls are working at the kernel level and interject themselves into a network connection outside of the DNS lookup process. You could reverse-dns lookup the IP, which Little Snitch tries, but with things like CDNs and AWS EC2, you end up with a lot of reports of applications trying to connect to "foo.akamai.com" OR bar.akamai.com", where foo and bar are entirely separate entities, or just simply to ec2-0.1.2.3.aws.amazonaws.com or what-have-you. Little Snitch appears to maintain it's own cache of DNS entries as well, so if you've got one application that connects to some CDN's IP via it's own CNAME, many times other applications will appear to be connecting to the first application's CNAME when they attempt to connect to the same IP because LS has resolved that IP to the first CNAME more times, or first, or something like that.

It's not perfect, and frequently it isn't even helpful.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#224
post #152

Earlier quoted context omitted.

I handle this for my whole network with a pi-hole[0]. [0] https://pi-hole.net

When I tried pi-hole I was amazed by it. Until the day I discovered someone in China hacked it :-///

I got tons of shh login attempts from Russia and China. I just install fail2ban.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#225
post #57

Earlier quoted context omitted.

That comment makes me chuckle. These days, I have close to zero faith in commercial software that is "free", assuming that the business model is selling my data. I happily paid for Little Snitch and was comforted by the fact that I was the customer.

This comment makes me chuckle. The idea that since you pay for something means that the company won't sell your data.

I didn't mean to mock the sentiment and you're absolutely right to take a very cynical approach these days to any privacy promises.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#226

The author is not subtle in letting know that this is intended to be open source replacement for Little Snitch (domain!). But at-least macOS has little snitch, closest for Linux was opensnitch which was announced on HN few months back - https://github.com/evilsocket/opensnitch/ but I'm not sure whether it's actively being developed though.

No sadly Opensnitch is dead. Evilsocket for whatever reason went back to OSX and I (who was the other large contributor) did not feel the motivation to work on the project anymore.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#228
post #222

Earlier quoted context omitted.

Vanishingly few. Occasionally, I'm browsing the web and hit a text link that takes me to the browser's "I can't find this site" default screen. This usually happens with sponsored links that are not served from ad networks yet link to known ad sites.

My wife frequently complains about sponsored Google searches not resolving. She doesn't want to use an in-browser adblock, so the links will still appear, but aren't usable. Also, many redirecting analytics services from emails get blocked. Personally, I don't find these to be breaking issues for my use. My only issue is that the PiHole interface's administrative features are authenticated via the PiHole's service us…

All good points. I avoid some of the headache by not using the actual PiHole software, and therefore not bringing along whatever credential baggage that comes with. Just dnsmasq, and cron to update the blocklist. My setup runs directly on my router as well, eliminating the need to maintain another box.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#229
post #222

Earlier quoted context omitted.

My wife frequently complains about sponsored Google searches not resolving. She doesn't want to use an in-browser adblock, so the links will still appear, but aren't usable. Also, many redirecting analytics services from emails get blocked. Personally, I don't find these to be breaking issues for my use. My only issue is that the PiHole interface's administrative features are authenticated via the PiHole's service us…

All good points. I avoid some of the headache by not using the actual PiHole software, and therefore not bringing along whatever credential baggage that comes with. Just dnsmasq, and cron to update the blocklist. My setup runs directly on my router as well, eliminating the need to maintain another box.

Care to share your setup? Perhaps via a Gist?

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#230

Earlier quoted context omitted.

The people who developed the creative commons licenses recommend against using them for software. [From their FAQ]( https://creativecommons.org/faq/#can-i-apply-a-creative-comm... ): > We recommend against using Creative Commons licenses for software. Instead, we strongly encourage you to use one of the very good software licenses which are already available. We recommend considering licenses made available by the Fr…

That's because we treat software very differently from most other content subject to copyright. As in this case, (reading the above threads) there's confusion as to the no commercial use clause extends to the content or the outcome of its processes. That is to say, NoCommercialUse for a book clearly means for derivative works. Nobody would ever suggest you can't read a book while in a commercial establishment. But in…

I completely agree with your first sentence. But I think your interpretation of NonCommercial is a bit off. NonCommercial in the context of a book does not refer to "using" the book or to creating derivatives. You don't need a license to read a book. Rather, it refers to copying the book. They have a separate clause that refers to creating derivative works from the book. If you have a CC-BY-NC book, that means you're allowed to copy the book as much as you want as long as it's not for commercial purposes. If you have a CC-BY book, that means you can copy it as much as you want, even if it's for commercial purposes. If you have CC-BY-ND, that means even though you can copy the book as much as you want, even for commercial purposes, the author is not granting you the right to make derivatives.

Software is different because copying software is a necessary part of using it. So CC-BY-NC for software could quite reasonably be read to restrict its use in a commercial environment because you (notionally) need a license to make that copy from the internet to your hard drive, and from your hard drive to system RAM so that you can use it.

Post reply on HN