This really should be built into every OS or DE at this point. I don't put sim cards in my phones anymore, and instead use a portable LTE VPN travel router (which runs OpenWRT, on which I have root) because of the things I learned over the last decade from apps like this. There should be per-host, per-app permissions in any OS that claims to care about privacy, just as Apple recently added per-directory, per-app perm…
Lulu – Mac open-source firewall that aims to block unknown outgoing connections
51–60 of 158 posts
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#52Earlier quoted context omitted.
Does this mean Mac users are not really root on their own machines?
Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode. Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64). So to answer you question - 'root' user on macOS is by default not a true r…
The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thing that requires write access to those folders is also capable of figuring out how to turn off SIP?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#53Earlier quoted context omitted.
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#54What about the same for Linux? I would pay twice the LittleSnitch price for it if it was working really good.
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#55I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)
These attempts* go on 24/7 even with 0 apps open and the computer being idle.
* https://i.imgur.com/md2ykLl.png
helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle goes on and on and on. Nevermind that they have the metadata to track every launch of every app on your OS.
Then you've got Adobe who is apparently convinced that by virtue of installing their software, they own the resources on your machine and network to their heart's content and spam non-stop phone-home messages to adobess.com adobesc.com adobe.io etc etc
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#56I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#57Earlier quoted context omitted.
Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode. Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64). So to answer you question - 'root' user on macOS is by default not a true r…
It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…
It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#58Earlier quoted context omitted.
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#59I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)
I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#60Earlier quoted context omitted.
It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…
It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?