Be aware there are a few concerning open issues like it blocking all network requests when disabled: https://github.com/objective-see/LuLu/issues/264 or not being able to login after installing (due to security patch needing to be installed) https://github.com/objective-see/LuLu/issues/284
Lulu – Mac open-source firewall that aims to block unknown outgoing connections
81–90 of 158 posts
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#82Has totally replaced Little Snitch for me recently after being increasingly annoyed by it over a decade of using it. This type of software requires lots of trust in the developer and objective-see has earned that trust with the many great projects they provide.
I miss how LS was much more granular in allowing specific connections. In Lulu when I approve an app, it's all app's connections by default, unless I am creative with a regex to capture proper connections. That's a major downside compared to LS. Or am I missing something?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#83Earlier quoted context omitted.
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?
They never claimed to be the 'privacy king'. They just suggested it, and people took the bait.
Apple is a company, and as such are only allowed to care about their bottom line. If privacy aligns with their bottom line, they'll use it for easy advertisement and goodwill, but if it doesn't then they'll forego privacy just as easily.
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#84Earlier quoted context omitted.
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#85I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
There are currently 3 ways I know of to block them:
1. Exclusions Blaster https://www.vallumfirewall.com/eblaster/
2. Enabling Little Snitch 4.6 kext under Big Sur https://www.obdev.at/support/littlesnitch/245913651253917
3. Convoluted hack: https://tinyapps.org/blog/202010210700_whose_computer_is_it....
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#86Is there something like this but for Windows?
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#87Earlier quoted context omitted.
It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?
> It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo? They never claimed to be the 'privacy king'. They just suggested it, and people took the bait. Apple is a company, and as such are only allowed to care about their bottom line. If privacy aligns…
That's a myth. It is neither descriptively the case, nor normatively an obligation, that a company maximise profits to the detriment of everything else. There is no such law, legal or economic. (There is shareholder value theory in economics which suggests that shareholder value maximisation is the optimal solution to the principal-agent problem, but that rests on very restrictive and utterly unrealistic conditions. Furthermore, shareholder value optimisation is not the same as short-term profit maximisation, either.)
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#88I'm gonna be the thick one. What advantages does it give me when I have something like pi-hole as my DNS server on the internal network? Surely majority of connections need a DNS resolution. Would love to see some stats showing the amount of blocked connections that bypassed DNS.
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#89Does this mean Little Snitch's days are numbered?
VERSION 1.0.0 (08/09/2018)
Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections
#90I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)
Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…
I'm aware of Gatekeeper checking developer certificates upon opening apps over an unencrypted connection (so far; Apple is fixing that), but not sure where the gross privacy invasion or security risk is (in particular compared to existing alternatives, not some platonic ideal).
Here, FWIW, is what Apple says about Gatekeeper and Notarization. I'd be eager to hear any evidence that this is incorrect.
> Gatekeeper performs online checks to verify if an app contains known malware and whether the developer’s signing certificate is revoked. We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices. > Notarization checks if the app contains known malware using an encrypted connection that is resilient to server failures.
> These security checks have never included the user’s Apple ID or the identity of their device. To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs.
> In addition, over the the next year we will introduce several changes to our security checks:
* A new encrypted protocol for Developer ID certificate revocation checks
* Strong protections against server failure
* A new preference for users to opt out of these security protections