Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

81–90 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#81
post #6

Be aware there are a few concerning open issues like it blocking all network requests when disabled: https://github.com/objective-see/LuLu/issues/264 or not being able to login after installing (due to security patch needing to be installed) https://github.com/objective-see/LuLu/issues/284

What a nice and user friendly operating system.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#82
post #65
post #7

Has totally replaced Little Snitch for me recently after being increasingly annoyed by it over a decade of using it. This type of software requires lots of trust in the developer and objective-see has earned that trust with the many great projects they provide.

I miss how LS was much more granular in allowing specific connections. In Lulu when I approve an app, it's all app's connections by default, unless I am creative with a regex to capture proper connections. That's a major downside compared to LS. Or am I missing something?

[deleted]

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#83
post #56

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

> It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

They never claimed to be the 'privacy king'. They just suggested it, and people took the bait.

Apple is a company, and as such are only allowed to care about their bottom line. If privacy aligns with their bottom line, they'll use it for easy advertisement and goodwill, but if it doesn't then they'll forego privacy just as easily.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#84
post #56

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

Maybe its because "privacy champion" is nothing but their marketing. They don't care about their users or their privacy one bit.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#85
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

> some Apple system software ... are whitelisted and cannot be blocked by the user even if they want to

There are currently 3 ways I know of to block them:

1. Exclusions Blaster https://www.vallumfirewall.com/eblaster/

2. Enabling Little Snitch 4.6 kext under Big Sur https://www.obdev.at/support/littlesnitch/245913651253917

3. Convoluted hack: https://tinyapps.org/blog/202010210700_whose_computer_is_it....

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#86
post #67

Is there something like this but for Windows?

I use malwarebytes after trying several options. It's merely a good interface to leverage windows firewall with a block-until allow dialogue box. For whatever reason, it's hard to find a firewall for windows that doesn't use a scammy freemium model.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#87
post #56

Earlier quoted context omitted.

It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo?

> It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo? They never claimed to be the 'privacy king'. They just suggested it, and people took the bait. Apple is a company, and as such are only allowed to care about their bottom line. If privacy aligns…

> Apple is a company, and as such are only allowed to care about their bottom line.

That's a myth. It is neither descriptively the case, nor normatively an obligation, that a company maximise profits to the detriment of everything else. There is no such law, legal or economic. (There is shareholder value theory in economics which suggests that shareholder value maximisation is the optimal solution to the principal-agent problem, but that rests on very restrictive and utterly unrealistic conditions. Furthermore, shareholder value optimisation is not the same as short-term profit maximisation, either.)

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#88

I'm gonna be the thick one. What advantages does it give me when I have something like pi-hole as my DNS server on the internal network? Surely majority of connections need a DNS resolution. Would love to see some stats showing the amount of blocked connections that bypassed DNS.

Malware (and I include in this definition several services shipped by the OS vendor) typically doesn't rely exclusively on DNS lookups. Many will fallback to hardcoded lists of IPv6 addresses if you blackhole DNS.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#89
post #3

Does this mean Little Snitch's days are numbered?

If so, then Little Snitch's days have been numbered for a while, as Lulu came out in 2018.

VERSION 1.0.0 (08/09/2018)

https://www.objective-see.com/products/changelogs/LuLu.txt

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#90
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

Could you enlighten me what the gross invasion of privacy and the security risk is for the majority of users that do not hack their machine in a way that prevents those connections?

I'm aware of Gatekeeper checking developer certificates upon opening apps over an unencrypted connection (so far; Apple is fixing that), but not sure where the gross privacy invasion or security risk is (in particular compared to existing alternatives, not some platonic ideal).

Here, FWIW, is what Apple says about Gatekeeper and Notarization. I'd be eager to hear any evidence that this is incorrect.

> Gatekeeper performs online checks to verify if an app contains known malware and whether the developer’s signing certificate is revoked. We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices. > Notarization checks if the app contains known malware using an encrypted connection that is resilient to server failures.

> These security checks have never included the user’s Apple ID or the identity of their device. To further protect privacy, we have stopped logging IP addresses associated with Developer ID certificate checks, and we will ensure that any collected IP addresses are removed from logs.

> In addition, over the the next year we will introduce several changes to our security checks:

* A new encrypted protocol for Developer ID certificate revocation checks

* Strong protections against server failure

* A new preference for users to opt out of these security protections

https://support.apple.com/en-us/HT202491

Post reply on HN