Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

41–50 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#41
post #24

Earlier quoted context omitted.

little snitch looks way better and has a better UX, so nope

Personally I find the LS interface way too complex and intimidating (and I say this as a long time macOS / iOS developer). Lulu has a quirky interface, but it's much clearer. Of course it also helps that it's free and open source.

You are a liar

Little Snitch: https://www.obdev.at/Images/littlesnitch/decide-immediately....

Lulu: https://objective-see.com/images/LL/adAlert.png

You are a liar

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#42
post #38

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

Does this mean Mac users are not really root on their own machines?

Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode.

Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64).

So to answer you question - 'root' user on macOS is by default not a true root in unix sense, but can be trivially turned into one by booting computer in recovery mode and running single command in Terminal. Restart into recovery mode is required so that malicious applications cannot change it on their own, even if they would use unknown privilege escalation technique.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#43
post #31

Earlier quoted context omitted.

Ok, thank you for a clue, I'll give it a try. The last time I checked it was clearly very far from production-ready. It still shouts "this software is a work in progress, do not expect it to be bug free and do not rely on it for any type of security" in all caps on its homepage which suggests it still is. Given all the abandoned attempts I've seen in the past I also feel very skeptical this one too.

Would you mind sharing your experience afterwards? The alternatives to SELinux in terms of network filtering seem to be so rare.

I can give you mine, since I use(d) opensnitch for a while.

It works quite well but requires a GUI (obviously), it looks like it primarily supports GTK. If you're hoping to use the machine purely from the CLI (like, when sshing into your work machine) it won't work well.

It is significantly less powerful than LittleSnitch, some options don't exist (like, allowing access to a domain), but you get similar functionality in many cases.

Overall, it's definitely worth testing out to see if it works for you.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#44
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#45
post #40

Earlier quoted context omitted.

I'm curious about this, as it's one of 3 kexts that I get warned about support being withdrawn in a future version of macOS (UAD being one of the others, I forget the 3rd). I could probably live without LS, but the UAD support being withdrawn is quite concerning given the level of investment I have there.

The latest version of LS doesn't use kernel extensions any more as it's using the new network filter stack provided by the OS.

OK, I see that it's now at version 5, so I guess another paid upgrade required when I finally move my machine to Big Sur.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#48

I'm gonna be the thick one. What advantages does it give me when I have something like pi-hole as my DNS server on the internal network? Surely majority of connections need a DNS resolution. Would love to see some stats showing the amount of blocked connections that bypassed DNS.

This allows you to block the connections per-app, and before they happen for the first time.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#49
This really should be built into every OS or DE at this point.

I don't put sim cards in my phones anymore, and instead use a portable LTE VPN travel router (which runs OpenWRT, on which I have root) because of the things I learned over the last decade from apps like this.

There should be per-host, per-app permissions in any OS that claims to care about privacy, just as Apple recently added per-directory, per-app permissions to fight ransomware.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#50
post #24

Earlier quoted context omitted.

little snitch looks way better and has a better UX, so nope

Personally I find the LS interface way too complex and intimidating (and I say this as a long time macOS / iOS developer). Lulu has a quirky interface, but it's much clearer. Of course it also helps that it's free and open source.

Any comment about cannot login in the first comment. May give it a try but if ...
Post reply on HN