Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

111–120 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#111

Earlier quoted context omitted.

Care to share?

This is mine from 2019: sudo killall ACCFinderSync “Core Sync” AdobeCRDaemon “Adobe Creative” AdobeIPCBroker node “Adobe Desktop Service” “Adobe Crash Reporter” I should probably stick it in Automator or something because Adobe's invasion is getting really annoying.

launchd sounds scary but it is not that hard to get an agent enabled. It's basically a plist file or two in the right place and a command to enable it. You can have launchd call your shell script once per minute.

I used this to good effect once to log the output of a few debug commands to text, commit that to a git repo, and move on. Then I could come back later and see what was going on before an issue happened on that system.

Here's some info on launchd to save you some searching: https://www.maketecheasier.com/use-launchd-run-scripts-on-sc...

Regarding finding the adobe process names, you can filter output of `ps aux` based on application path or name to get a current list process IDs and kill those.

In this particular case, watch out for getting into a launchd fight, where launchd is simultaneously killing adobe processes and also relaunching them because of Adobe's own launchd registrations.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#112

Earlier quoted context omitted.

I was tired of seeing 7+ Adobe background daemons, launchagents, helpers, brokers, core sync, etc crap that they decided must be running constantly. I made a script that fires every hour and if no Adobe apps are running it just kills all those useless processes. My machine is so much happier now.

Care to share?

Sure. It requires a tiny bit of setup, but I put up a gist[0].

You can customize to your needs/liking, let me know if it works for you...

[0]: https://github.com/luckman212/adobe_kill

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#113

Earlier quoted context omitted.

> It it too much to ask to have the normal security protections that macOS provides and still being able to block Apple services with Little Snitch or Lulu or letting Apple services go through a VPN as well? This. Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Instead they could easily allow the user to customi…

> Apple is making the use of many security functions black or white: either you allow complete control by Apple, or you have little to no protection at all. Wow, thank you for providing a perfect example of what I mean. I specifically brought up upgrading bash because that was the use case that prompted me to actually learn about SIP. It took me all of fifteen minutes to read a few docs on it, restart and disable it,…

I understand where you’re coming from. My critique was a bit misdirected.

I guess what is behind it is my frustration and anger with the increasing widespread acceptance of black box computing devices - which are supposedly ‘user controlled general purpose computers’, yet are increasingly not, and which are instead actively spying on us and policing us in a million different ways.

[Edit: what follows is an articulation of various things I’m currently witnessing (a stream of consciousness), as well as frameworks I’m currently learning to apply, that I want to record for myself and others - potential allies who are concerned with this as well]

I’m angry that our overall tech and science literacy is constantly decreasing. I’m angry that a lot of things are getting more and more locked in (Tivoization), blocking learning and making it increasingly unfriendly for beginners

What this looks like in practice is that the essential/necessary ‘ladders‘ to learn and accomplish something (the age and current-skill level -appropriate materials or tools/technologies) are kicked away, with those who kicked it away (locking it away) claiming that they did not use those ladders themselves. They instead claim others can follow in their footsteps - without having, or being given, access to the very same ladders they needed to climb up themselves. This is bourgeois gatekeeping. There’s a book written about an economic theory by economist Ha-Joon Chang, called ‘Kicking Away The Ladder’, that I believe illustrates this well:

“How did the rich countries really become rich? In this provocative study, Ha-Joon Chang examines the great pressure on developing countries from the developed world to adopt certain 'good policies' and 'good institutions', seen today as necessary for economic development. Adopting a historical approach, Dr Chang finds that the economic evolution of now-developed countries differed dramatically from the procedures that they now recommend to poorer nations. His conclusions are compelling and disturbing: that developed countries are attempting to 'kick away the ladder' with which they have climbed to the top, thereby preventing developing counties from adopting policies and institutions that they themselves have used.”

The two main strategies originally used by the global north as they developed, yet which global south countries are now denied access to in north-south relations, are: protectionism and government subsidies.

The exploitation that happens today on a large scale between north-south, seen in the way global south countries are plundered and abused by the global north capitalist firms and governments, is the same phenomenon that we see (on a smaller scale) in the global north capitalist education system, where rich capitalists can get their children tutoring and give them much more patience and attention (as well as opportunities to take over a family business or other non waged intellectual labor - in opposition to waged manual labor - and a chance to develop favorable relationships with other capitalists) than parents of working class children, perpetuating antagonistic class relations.

-

Also I shouldn’t be talking about MacOS internals (SIP, etc.) because I don’t know enough about it yet.

Thanks for clarifying, and no, please do not wear any such badges!

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#114
post #97
post #81

Earlier quoted context omitted.

What a nice and user friendly operating system.

What kind of argument is this? It’s a single app... how can you judge an operating system off of something that a) probably hasn’t been updated to support changes or b) kinda buggy because it happens to be a fairly invasive program.

Without saying anything about OSX in particular, any operating system that requires network access to log in is a user-hostile piece of shit, and the linked bug#284 pretty well implies that that is in fact the case. It's entirely possible that the problem is due to incompatibities with new OS code or bugs in the firewall program (edit: ie, your case a and case b), but evidence in the bug report pretty clearly suggests that the firewall is correctly blocking all non-whitelisted network requests, and the failure to log in is due to the OS maliciously trying to phone home against the user's wishes.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#115
post #93

Earlier quoted context omitted.

I'm aware no one asked, but in case anyone was scanning for Windows, simplewall is a reasonable alternative, both free and open source (development powered by donations): https://www.henrypp.org/product/simplewall I'm not affiliated with them.

We're working on a powerful (also FOSS!) alternative for Windows. It includes DNS-over-TLS and extensive firewall features. See https://safing.io/portmaster/ It's not completely stable yet, but we are making great progress. We'd love feedback!

Portmaster looks nothing short of amazing. I have tried it some two months ago but for couldn't really get along with it, I can't remember why. I should try it again, many thanks!

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#117

I have LuLu installed on an old MacBook Pro and it does work well. It comes with preset rules to allow most of the essential apps communicate with Apple but they can be overridden to stop my computer from even getting the NPT time.

NTP*

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#118
post #10

I wonder how this works with respect to apple's "special exemptions" for its own applications. (bypass NEFilterDataProvider)

I recently learned that even blackholing the entire /8 block of Apple's IPs at the router, after they bypass your provided DNS servers, after they bypass your /etc/hosts file, macOS then tries to phone home using IPv6. These attempts* go on 24/7 even with 0 apps open and the computer being idle. * https://i.imgur.com/md2ykLl.png helpd, geod, locationd, cloudd, the list of apps phoning home when your computer is idle…

I have quite a restrictive firewall. Like an old school one: accept the necessary, drop the rest. Found my Mac unusable in these conditions. It always tries to phone home unsuccessfully, so freezes. Then freezes again. It has the offline mode but it has no firewalled mode unfortunately. Once the cable is inserted it keeps trying.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#119
post #6

Be aware there are a few concerning open issues like it blocking all network requests when disabled: https://github.com/objective-see/LuLu/issues/264 or not being able to login after installing (due to security patch needing to be installed) https://github.com/objective-see/LuLu/issues/284

Both issues with Big Sur. An operating system I won't be running for 9-12 months. I'm confident the issues will be cleared up by then.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#120
post #73

Earlier quoted context omitted.

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user). Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable…

I'm taking a more mild approach, switching to lugging two laptops around. One is for DevOps, accessing production systems, servers. That's where my ssh keys will reside. This will run qubes or maybe NixOS. Not sure yet. The Mac will be left for casual daily use, development (but no production keys), graphics design, fun, general browsing, chat, and whatnot. I'm still in the process of splitting all my tasks into what…

I actually switched to Windows, and I use WSL2 to run a really seamless Linux shell that lets me do all my dev work.

So far it really has been the best of both worlds.. For my particular work, I haven't missed my Mac at all.. The developer experience has been basically identical.

Post reply on HN