Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

101–110 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#101

Works great. I replaced Little Snitch with it. I like it's simple interface and simple value proposition.

> I replaced Little Snitch with it.

Did you purchase a Little Snitch licence?

I wonder why someone would go with LuLu if they've already paid for Little Snitch, when LuLu has fewer features.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#102
I use it for a long time now, nice piece of software. The only problem I have is related to requests per app.

For example, a Sublime Text plug-in (TabNine), even if I allow permanently outgoing connections the plug-in has to make, LuLu will keep asking me for permissions next time.

There is an issue open for that matter but no fix yet apparently: https://github.com/objective-see/LuLu/issues/147

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#103
post #85

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

> some Apple system software ... are whitelisted and cannot be blocked by the user even if they want to There are currently 3 ways I know of to block them: 1. Exclusions Blaster https://www.vallumfirewall.com/eblaster/ 2. Enabling Little Snitch 4.6 kext under Big Sur https://www.obdev.at/support/littlesnitch/245913651253917 3. Convoluted hack: https://tinyapps.org/blog/202010210700_whose_computer_is_it....

Oh neat, they're still maintaining Little Snitch 4 for Big Sur for people who want a kext and don't mind approving it.

They say "that option could go away at any time", but that would require Apple to make SIP mandatory, and I still don't see that happening. There may come a time, however, where you need to actually disable part of SIP.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#104

Earlier quoted context omitted.

I have the impression that Apple's privacy marketing was just an opportunity grab because they noticed they were doing slightly better than competitors. The recent reveal of MacOS calling home and lack of any significant reaction is a strong indicator this was all just lip service.

Spot-on - it is just a lip-service, and initiated after Jolla launched its Sailfish OS phone. Jolla was started by a bunch of ex-Nokia engineers who were working on the next-gen mobile OS, before Microsoft scuttled it. The Jolla phone outsold the iPhones in some countries in Europe when it was launched ( https://www.gsmarena.com/jolla_outsells_iphone_5c_and_iphone... ). Unfortunately, they couldn't maintain their mom…

A key supporting point to this theory: Apple does not encrypt user iCloud backups end-to-end[1].

1. https://support.apple.com/en-us/HT202303

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#105
post #90

Earlier quoted context omitted.

Threre are no indications that Apple is willing to compromise and allow application firewalls to block Apple softwares that Apple believes should be able to access the internet, even if the user doesn't want it too. It's a gross invasion of privacy, and a security risk. (By the way, even in Lulu, some Apple system software - apsd, automount, helpd, mDNSResponder, mount_nfs, mount_url, ocspd, sntp, trustd - are whitel…

Could you enlighten me what the gross invasion of privacy and the security risk is for the majority of users that do not hack their machine in a way that prevents those connections? I'm aware of Gatekeeper checking developer certificates upon opening apps over an unencrypted connection (so far; Apple is fixing that), but not sure where the gross privacy invasion or security risk is (in particular compared to existing…

> Could you enlighten me what the gross invasion of privacy and the security risk is for the majority of users

The same reasons that people use application firewalls on their system - Access to our personal data by Apple - intentionally or "accidently". Malware may be able to hijack Apple whitelisted softwares to do their mischief. (And please don't reply by saying we can "trust" Apple with our data - I don't, and if I have paid for a computer I consider it mine, not Apple's to meddle with it as they please).

As for the Gatekeeper incident, the only comment I have to add is that I really don't care about Apple's "apology" after they have been caught ...

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#106

Earlier quoted context omitted.

The first firewall to do this should definitely lead with that in the headline.

Downvote? I'm confused. This whole "Apple gets to bypass firewalls" thing is IMO a huge deal. Whoever figures out how to make a system-wide firewall that can block everything including "unblockable" Apple network traffic likely deserves (again: IMO) all the attention we can give them.

This already exists. Apple processes can bypass app-specific filters (NEFilterDataProvider), but not system-wide firewalls (like the built-in BPF), VPN configurations, etc.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#107
post #33

Earlier quoted context omitted.

iptables?

iptables don't let you know when a particular program tries to access an outside host and choose whether you want to allow that. Speaking of a desktop (not a server) firewall I'm rarely even interested which host/port/whatever is a connection about. What matters to me is what app initiated it (if it's initiated from outside my PC it should be always blocked). Iptables used to expose a field attributing a connection t…

Seems like you could do something with ebpf but how would you deal with the notifications in a cli env... special tty you connect to via tmux/screen?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#108
post #73

Earlier quoted context omitted.

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user). Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable…

I'm taking a more mild approach, switching to lugging two laptops around. One is for DevOps, accessing production systems, servers. That's where my ssh keys will reside. This will run qubes or maybe NixOS. Not sure yet. The Mac will be left for casual daily use, development (but no production keys), graphics design, fun, general browsing, chat, and whatnot. I'm still in the process of splitting all my tasks into what…

I just installed nix on my 2011 Mac mini on High Sierra. With home-manager, it’s an incredibly capable brew replacement

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#109

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customi…

> Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all.

Wow, thank you for providing a perfect example of what I mean.

I specifically brought up upgrading bash because that was the use case that prompted me to actually learn about SIP. It took me all of fifteen minutes to read a few docs on it, restart and disable it, upgrade to Bash 5...and re-enable SIP and move on with my day, because the dichotomy of "complete control" and "little to no protection" you're presenting here is an egregiously false one. But god forbid anybody actually learn about the platform they're criticising (and there are plenty of real things to criticise about macOS that aren't just projected fears from iOS) before clutching at pearls.

I came to macOS from Linux, and there most definitely are conflicts between what I want to do and what Apple thinks I should be doing. Astonishingly I've almost always been able to go ahead and do those things (barring a complete lack of functionality e.g. with dropping support for 32-bit libraries, an unsolvable dilemma I've managed to crack by...leaving one of my devices on Mojave) because I don't just sit on my hands and whine about it. Apparently this is defending a giant faceless corporation, so I should probably wear that badge with pride.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#110

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well?

Strangely enough you can re-enable SIP after making the changes you need to let you or your desired applications do what you want.
Post reply on HN