Live data from Hacker News

Lulu – Mac open-source firewall that aims to block unknown outgoing connections

objective-see.com

151–158 of 158 posts

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#151
post #149

Earlier quoted context omitted.

> You need to think about this from a security perspective An application firewall is a SECURITY software. Crippling it is stupid. And that is exactly why people are very pissed at Apple for doing so. > Apple did not “deliberately cripple” the firewall. Yes, they did - they crippled all APPLICATION firewalls. An application firewall controls what apps can access the internet. By deliberately creating a new API with a…

> There is no illusion - if you don't use iCloud, Maps, App Store etc., they don't need to unnecessarily connect to the internet and waste our bandwidth, or worse access and transfer our personal data Which is exactly what happens now. You’re spending a lot effort protecting against an imaginary problem rather than the kinds of attacks which actually cause problems. If this terrifies you so much, add some ipfw rules…

> Which is exactly what happens now.

No, it doesn't because I use an application firewall that BLOCKS them (I haven't upgraded to the crippled macOS). Moreover these are not "core" services and the OS functions fine even if they are blocked.

> If this terrifies you so much, add some ipfw rules and move on.

Why should I when the application firewalls I use are more user-friendly and require less effort? And why should Apple get to dictate what software I use or how I use it? (You may be fine with that and may have given in, some of us won't and we will be vocal about it).

> block it at the firewall so you don’t have to rely on Apple

No, Apple won't make me jump through hoops - the better plan is to DUMP apple if they refuse to value their customers needs. There are better alternate available.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#152
post #149

Earlier quoted context omitted.

> There is no illusion - if you don't use iCloud, Maps, App Store etc., they don't need to unnecessarily connect to the internet and waste our bandwidth, or worse access and transfer our personal data Which is exactly what happens now. You’re spending a lot effort protecting against an imaginary problem rather than the kinds of attacks which actually cause problems. If this terrifies you so much, add some ipfw rules…

> Which is exactly what happens now. No, it doesn't because I use an application firewall that BLOCKS them (I haven't upgraded to the crippled macOS). Moreover these are not "core" services and the OS functions fine even if they are blocked. > If this terrifies you so much, add some ipfw rules and move on. Why should I when the application firewalls I use are more user-friendly and require less effort? And why should…

> No, Apple won't make me jump through hoops - the better plan is to DUMP apple if they refuse to value their customers needs.

This was exactly what I suggested: if you’re paranoid about Apple’s intentions, switch OSes. Your level of distrust is never going to be satisfied by the decisions they make with the other 99.9999% of their customers in mind.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#153

Earlier quoted context omitted.

It's honestly mind-boggling how many people whine and complain about macOS not "letting" them do this or that when they can turn off virtually every one of their gripes in about two minutes. The most egregious was someone complaining that /bin and other system folders are read-only [on systems under System Integrity Protection]. Surely anybody with a pressing desire to e.g. upgrade their bash install or any other thi…

System directories are sealed as of Big Sur; disabling SIP is not enough to be able to modify them.

You can still modify them though. It's just, uh, annoying.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#154

Earlier quoted context omitted.

launchd sounds scary but it is not that hard to get an agent enabled. It's basically a plist file or two in the right place and a command to enable it. You can have launchd call your shell script once per minute. I used this to good effect once to log the output of a few debug commands to text, commit that to a git repo, and move on. Then I could come back later and see what was going on before an issue happened on t…

Speaking of launchd, it would be a much better idea to unload those services rather than just killing them so they don't come back.

Indeed. Some component of Adobe's suite will be responsible for re-enabling them, so it's just a balance between actually using the software and disabling the background tasks.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#155
post #73

Earlier quoted context omitted.

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user). Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable…

> I know this probably isn't what you're looking for ...

You know , actually after similar mileage with Macs I consider exactly the same solution. I started with Mac as escape from windows. It was fine for some time when Jobs was around and some time after that, but since 2015 I cannot choose Mac Book Pro that would just fit for work with all that idiocy with touch bars, malfunctioning keyboards and idiotic dongles, instead of working horse that has everything you need and makes things simpler.

>I'm sure Apple will continue to sell tons of Macs and that's fine...

And now as MBP 2015 had gracefully died after I provided the best care for it you can possibly imagine, I wish to move away from Macs even more. I do not wish to pay premium money for shitty equipment.

This 2015 model have just fallen apart, starting with screws that by some unknown to me reason where unscrewing themselves and you could not tight them back because some idiot made them non standard to make sure you really cannot do it, not even with the knife. Then I discovered that screen has traces of buttons after closing the lid. Then I discovered those small traces are unremovable. Then battery even with a proper care died anyway after third of cycles it suppose to have. Then screen have stopped working and then this shit have stopped booting completely ( even with external display). I should also mention power cord ( with cheap plastic) that became yellow and was not always connecting , while it was carefully kept from banding too much. HDMI that in critical situation did not work, with the best cable you can get. OS that was constantly confusing where the main screen is, forgetting the ‘mirror’ option at will and I can go on and on ....

Overall the experience is horrible. I have other models from previous years and nothing like that had happened.

And I am told MBP2015 is considered to be a best model, as after mid 2015 models are even worse, not mentioning connectivity that renders them useless for mobility I need.

So looking at the way Mac is made these days I am not at all convinced they would continue to sell ‘tons of Macs’ in the following years.

Only inertia saves in such situation but for how long? In my case I cannot move from the platform because I’ve decided to write a proper File Manager for Mac. It is almost complete and I simply cannot live without it. I also cannot leave it unfinished as this would be a huge waste of effort. So I’ll have to finish it, start selling it, and then port to other platforms.

>Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable.

For me too. Anyway, I’ve been exploring gnu/linux for some time now and it appears as the next step. Since Mac is dead I’ll have to stick with linux for a while. I have no other options available.

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#156
post #73

Earlier quoted context omitted.

I know this probably isn't what you're looking for, but for me personally the solution is to not upgrade past macOS 10.15, and to very likely not buy any more Mac laptops or desktops (after 15 years of being a Mac-first user). Obviously that's a personal choice, but for me losing that level of control of my desktop operating system - and seeing this as the start of a trend that will only get worse - is not acceptable…

I'm taking a more mild approach, switching to lugging two laptops around. One is for DevOps, accessing production systems, servers. That's where my ssh keys will reside. This will run qubes or maybe NixOS. Not sure yet. The Mac will be left for casual daily use, development (but no production keys), graphics design, fun, general browsing, chat, and whatnot. I'm still in the process of splitting all my tasks into what…

Of course it's annoying to carry around two laptops, but completely switching to Linux just means I won't make it happen. Maybe some time...

Unfortunately this setup will not always work with the mobility requirement. May be some small linux box instead ? But which one ?

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#157

Earlier quoted context omitted.

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

> What is the proper solution? Use a better OS. Seriously, just use Linux if you want that level of control. Most users are happy to give up control in exchange for pretty graphics, easy UI, etc.

I would agree actually. I learn linux, but to get into the depths takes some time. It’s not even easy to choose which one to use. And I have code written for Mac platform, that I need to finish. (I’ve described my situation above https://news.ycombinator.com/item?id=25778247 )

Re: Lulu – Mac open-source firewall that aims to block unknown outgoing connections

#158

Earlier quoted context omitted.

What is point then to have such app all? if you can’t control _all_ connections then it appears useless. What is the proper solution? Something on router? Is there a way? Can Openwrt do the job of protecting privacy properly?

It should be possible to block the IPs these Apple wares connect to. Currently the easiest solution I have found is ProtonVPN, which claims to block them - https://protonvpn.com/blog/big-sur-exclusion-list/ . (Ofcourse, the best solution is to not upgrade macOS and stick with macOS Mojave).

I tried to block some of the ip-s Mac was connecting to and then apps had stopped working. Back then I thought I did something wrong and didn’t have time to test it further but in light of recent events It could be I have stumbled on the issue with getting permissions for each app that made a lot of ‘good publicity’ for apple...
Post reply on HN