Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

61–70 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#61
post #56

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

They typically are in big companies. "If you're able to do your job, [Security/SecOps/IT] isn't doing theirs" and all that.

It's a natural outgrowth of a corporate "efficiency" mandate that puts functional groups together vs. cross-functional groups. That pendulum is ever swinging.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#62
post #51
post #49

This really should be built into every OS or DE at this point. I don't put sim cards in my phones anymore, and instead use a portable LTE VPN travel router (which runs OpenWRT, on which I have root) because of the things I learned over the last decade from apps like this. There should be per-host, per-app permissions in any OS that claims to care about privacy, just as Apple recently added per-directory, per-app perm…

Which portable trustworthy and can run openers?

yes.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#63

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customize, and make a selection that works for them (which was the standard in older versions of OSX - pre-Big Sur [1]). The above defending of a giant faceless corporation, by @filleduchaos, is what is mind-boggling.

This feature obviously helps protect some users (non tech-literate ones), but for many it means completely turning off many useful security features ('opting out' by turning off SIP) with a lack of any sort of granular control/customization, on a device they supposedly own. It's a shame this new capitalist encroachment on user privacy is met with such understanding.

[1] https://news.ycombinator.com/item?id=25078034, https://sneak.berlin/20201112/your-computer-isnt-yours/

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#64

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customi…

>Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all.

In that respect, no Apple's no different from Facebook's "agree to share your data or take a hike" move with WhatsApp

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#65
post #7

Has totally replaced Little Snitch for me recently after being increasingly annoyed by it over a decade of using it. This type of software requires lots of trust in the developer and objective-see has earned that trust with the many great projects they provide.

I miss how LS was much more granular in allowing specific connections. In Lulu when I approve an app, it's all app's connections by default, unless I am creative with a regex to capture proper connections. That's a major downside compared to LS. Or am I missing something?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#66
post #56

Earlier quoted context omitted.

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

I have the impression that Apple's privacy marketing was just an opportunity grab because they noticed they were doing slightly better than competitors. The recent reveal of MacOS calling home and lack of any significant reaction is a strong indicator this was all just lip service.

Spot-on - it is just a lip-service, and initiated after Jolla launched its Sailfish OS phone. Jolla was started by a bunch of ex-Nokia engineers who were working on the next-gen mobile OS, before Microsoft scuttled it. The Jolla phone outsold the iPhones in some countries in Europe when it was launched ( https://www.gsmarena.com/jolla_outsells_iphone_5c_and_iphone... ).

Unfortunately, they couldn't maintain their momentum and had to get out of the business of making phones. (They still make their mobile OS, and you can buy a license for it and install it on some Sony phones).

At that time, Apple even had an ad-network for apps, and had got embroiled in the PRISM scandal (Apple, and other American corporate were selling their users data to US government agencies - https://www.theguardian.com/world/2013/jun/06/us-tech-giants... ).

Jolla was marketed with a focus on privacy.

To counter the bad publicity and the threat from a potential startup, they partly shut-down their ad-network ( https://appleinsider.com/articles/16/01/15/apple-to-shut-dow... ) and started marketing their new found love for privacy.

But from the get-go, it was never about user privacy - their goal was to ensure that the users data remained siloed within their eco-system, and their competitors couldn't get access to it. They also used the "privacy" angel as an excuse to further close down their devices, and make it incompatible with anything not approved by them.

(Note that it was due to their ad-network and because Apple wants access to users data that iPhones / iPad don't give you the ability to control what app can or cannot connect to the internet. This is still the case, except if you are on cellular data; if you are on Wifi though, an app cannot be blocked. While all the new labeling "transparency" feature and telling the user what data an app will gather from you is good, the feature that would really benefit every one better is the ability to block apps from connecting to the internet itself in the first place!).

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#68
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…

PiHole?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#70

Earlier quoted context omitted.

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

“This solution is not completely perfect so it's absolutely worthless”.

"This lock doesn't really prevent unauthorized access to this room but you know, 'perfect is the enemy of good!'"
Post reply on HN