Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

51–60 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#51
post #49

This really should be built into every OS or DE at this point. I don't put sim cards in my phones anymore, and instead use a portable LTE VPN travel router (which runs OpenWRT, on which I have root) because of the things I learned over the last decade from apps like this. There should be per-host, per-app permissions in any OS that claims to care about privacy, just as Apple recently added per-directory, per-app perm…

Which portable trustworthy and can run openers?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#52
post #38

Earlier quoted context omitted.

Does this mean Mac users are not really root on their own machines?

Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode. Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64). So to answer you question - 'root' user on macOS is by default not a true r…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes.

The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thing that requires write access to those folders is also capable of figuring out how to turn off SIP?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#53

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

“This solution is not completely perfect so it's absolutely worthless”.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#54

What about the same for Linux? I would pay twice the LittleSnitch price for it if it was working really good.

OpenSnitch (Linux) works great, but you can also browse through: https://awesomeopensource.com/projects/firewall

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#55
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6.

These attempts* go on 24/7 even with 0 apps open and the computer being idle.

* https://i.imgur.com/md2ykLl.png

helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle goes on and on and on. Nevermind that they have the metadata to track every launch of every app on your OS.

Then you've got Adobe who is apparently convinced that by virtue of installing their software, they own the resources on your machine and network to their heart's content and spam non-stop phone-home messages to adobess.com adobesc.com adobe.io etc etc

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#56
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#57

Earlier quoted context omitted.

Users can develop and install custom kernel extensions (.kexts) that can access everything, but they first need to disable System Integrity Protection in recovery mode. Over the years Apple expanded their frameworks library to reduce need for custom .kexts, but they are still supported even on M1 Macs (as long as they are compiled for ARM64). So to answer you question - 'root' user on macOS is by default not a true r…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes.

It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#58
post #56

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

I have the impression that Apple's privacy marketing was just an opportunity grab because they noticed they were doing slightly better than competitors. The recent reveal of MacOS calling home and lack of any significant reaction is a strong indicator this was all just lip service.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#59
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…

I was tired of seeing 7+ Adobe background daemons, launchagents, helpers, brokers, core sync, etc crap that they decided must be running constantly. I made a script that fires every hour and if no Adobe apps are running it just kills all those useless processes. My machine is so much happier now.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#60

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

[deleted]
Post reply on HN