Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

71–80 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#71

Earlier quoted context omitted.

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…

I was tired of seeing 7+ Adobe background daemons, launchagents, helpers, brokers, core sync, etc crap that they decided must be running constantly. I made a script that fires every hour and if no Adobe apps are running it just kills all those useless processes. My machine is so much happier now.

Care to share?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#72
post #33

What about the same for Linux? I would pay twice the LittleSnitch price for it if it was working really good.

iptables?

iptables don't let you know when a particular program tries to access an outside host and choose whether you want to allow that.

Speaking of a desktop (not a server) firewall I'm rarely even interested which host/port/whatever is a connection about. What matters to me is what app initiated it (if it's initiated from outside my PC it should be always blocked).

Iptables used to expose a field attributing a connection to a particular process but this feature was only available in old 2.4.x kernels IIRC.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#73

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user).

Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable, so I will look to other OSes to do my work.

I'm sure Apple will continue to sell tons of Macs and that's fine...

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#74

Earlier quoted context omitted.

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customi…

>Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. In that respect, no Apple's no different from Facebook's "agree to share your data or take a hike" move with WhatsApp

It's extremely different. In Apple's case we're talking about a personal computer that someone paid a few thousand dollars for and is their general purpose machine for their own private affairs (unrelated to Apple), and in Facebook's case you're talking about a single-purpose centralized communication app that is free.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#75

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

It should be possible to block the IPs these Apple wares connect to. Currently the easiest solution I have found is ProtonVPN, which claims to block them - https://protonvpn.com/blog/big-sur-exclusion-list/ .

(Ofcourse, the best solution is to not upgrade macOS and stick with macOS Mojave).

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#76

Earlier quoted context omitted.

“This solution is not completely perfect so it's absolutely worthless”.

"This lock doesn't really prevent unauthorized access to this room but you know, 'perfect is the enemy of good!'"

That excessive. Installing a lock to which the building owner owns a key is still an improvement over not installing a lock at all.

There's a difference between "All your connections are wide open, so any malicious or compromised software can connect to the web" and "Apple can connect to the web, so you have to decide whether to trust Apple."

I mean, if you're on a mac and you don't trust Apple not to be secretly keylogging your passwords or something, I think a firewall isn't going to help you.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#77
post #56

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

No, it is a deliberate business decision - they are moving towards converting the macOS into a closed sytem like ios.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#78

Earlier quoted context omitted.

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…

PiHole?

Pi-hole can only block DNS requests, it won't help against connecting directly to ipv4 or ipv6 addresses.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#79
post #76

Earlier quoted context omitted.

"This lock doesn't really prevent unauthorized access to this room but you know, 'perfect is the enemy of good!'"

That excessive. Installing a lock to which the building owner owns a key is still an improvement over not installing a lock at all. There's a difference between "All your connections are wide open, so any malicious or compromised software can connect to the web" and "Apple can connect to the web, so you have to decide whether to trust Apple." I mean, if you're on a mac and you don't trust Apple not to be secretly key…

Oh, the comment was only addressed to GP and a misused meme.

It is -not- a comment on LuLu or the substantial and valuable contributions and efforts of the developer in question. Hats off to him.

https://www.objective-see.com/

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#80
post #67

Is there something like this but for Windows?

Yes, I used to use TinyWall ( https://tinywall.pados.hu/ ), which is light and simple. But, if I remember right, it uses Windows built in firewall and so I don't know if it can completely block some Windows 10 system software from contacting Microsoft.

ZoneAlarm also used to be good, but used more resources and is not free - https://www.zonealarm.com/software/firewall (note that you do not need their crap browser extensions that it will ask you to install).

Post reply on HN