Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

91–100 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#91

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customi…

> This feature obviously helps protect some users (non tech-literate ones), but for many it means completely turning off many useful security features [...]

I'm pretty sure you have the "some" and "many" the wrong way around. In reality, this feature protects many users (non tech-literate ones), but for some that feel the need to turn it off, it, well, won't protect them, because it's turned off.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#92
post #73

Earlier quoted context omitted.

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user). Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable…

I'm taking a more mild approach, switching to lugging two laptops around.

One is for DevOps, accessing production systems, servers. That's where my ssh keys will reside. This will run qubes or maybe NixOS. Not sure yet.

The Mac will be left for casual daily use, development (but no production keys), graphics design, fun, general browsing, chat, and whatnot.

I'm still in the process of splitting all my tasks into what should be secure and what shouldn't.

A nice side effect is that I won't be just as afraid of running a random "brew install" or install an app to check it out, since the Mac is anyway going to be low-security.

Of course it's annoying to carry around two laptops, but completely switching to Linux just means I won't make it happen. Maybe some time...

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#93

What about the same for Linux? I would pay twice the LittleSnitch price for it if it was working really good.

I'm aware no one asked, but in case anyone was scanning for Windows, simplewall is a reasonable alternative, both free and open source (development powered by donations): https://www.henrypp.org/product/simplewall I'm not affiliated with them.

We're working on a powerful (also FOSS!) alternative for Windows. It includes DNS-over-TLS and extensive firewall features. See https://safing.io/portmaster/

It's not completely stable yet, but we are making great progress. We'd love feedback!

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#94

What about the same for Linux? I would pay twice the LittleSnitch price for it if it was working really good.

We're working on a powerful FOSS alternative for Linux. It includes DNS-over-TLS and extensive firewall features. See https://safing.io/portmaster/

It's not completely stable yet, but we are making great progress. We'd love feedback!

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#95
post #67

Is there something like this but for Windows?

We're working on a powerful (also FOSS!) alternative for Windows. It includes DNS-over-TLS and extensive firewall features. See https://safing.io/portmaster/ It's not completely stable yet, but we are making great progress. We'd love feedback!

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#96
post #87

Earlier quoted context omitted.

> It’s one of their weirder decisions. You can’t claim to be privacy king while simultaneously doing something like this. Maybe this is caused by Apple departments being siloed. The privacy champions are in a different silo? They never claimed to be the 'privacy king'. They just suggested it, and people took the bait. Apple is a company, and as such are only allowed to care about their bottom line. If privacy aligns…

> Apple is a company, and as such are only allowed to care about their bottom line. That's a myth. It is neither descriptively the case, nor normatively an obligation, that a company maximise profits to the detriment of everything else. There is no such law, legal or economic. (There is shareholder value theory in economics which suggests that shareholder value maximisation is the optimal solution to the principal-ag…

Of course they are talking about the fiduciary duty of directors to act in the best interest of the company (which is not a myth).

And who says that profit maximization necessarily has to be "short-term"? Clearly, marketing themselves on strong privacy guarantees is a long-term strategy.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#97
post #81
post #6

Be aware there are a few concerning open issues like it blocking all network requests when disabled: https://github.com/objective-see/LuLu/issues/264 or not being able to login after installing (due to security patch needing to be installed) https://github.com/objective-see/LuLu/issues/284

What a nice and user friendly operating system.

What kind of argument is this? It’s a single app... how can you judge an operating system off of something that a) probably hasn’t been updated to support changes or b) kinda buggy because it happens to be a fairly invasive program.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#98
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

The first firewall to do this should definitely lead with that in the headline.

Downvote? I'm confused. This whole "Apple gets to bypass firewalls" thing is IMO a huge deal.

Whoever figures out how to make a system-wide firewall that can block everything including "unblockable" Apple network traffic likely deserves (again: IMO) all the attention we can give them.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#99
post #33

Earlier quoted context omitted.

iptables?

iptables don't let you know when a particular program tries to access an outside host and choose whether you want to allow that. Speaking of a desktop (not a server) firewall I'm rarely even interested which host/port/whatever is a connection about. What matters to me is what app initiated it (if it's initiated from outside my PC it should be always blocked). Iptables used to expose a field attributing a connection t…

Plus if you use docker iptables are essentially useless without a lot of tweaking to make docket respect it.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#100

Earlier quoted context omitted.

I was tired of seeing 7+ Adobe background daemons, launchagents, helpers, brokers, core sync, etc crap that they decided must be running constantly. I made a script that fires every hour and if no Adobe apps are running it just kills all those useless processes. My machine is so much happier now.

Care to share?

This is mine from 2019:

  sudo killall ACCFinderSync “Core Sync” AdobeCRDaemon “Adobe Creative” AdobeIPCBroker node “Adobe Desktop Service” “Adobe Crash Reporter”
I should probably stick it in Automator or something because Adobe's invasion is getting really annoying.
Post reply on HN