Live data from Hacker News

LuLu: An open-source macOS firewall that blocks unknown outgoing connections

objective-see.com

181–190 of 252 posts

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#181

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

At some point a blocking list /app will break a site you use. Adblockers have broken sites for me countless times.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#182

Earlier quoted context omitted.

I want to drop that list into little snitch. In fact, when I install Little Snitch, I want it to ask me "would you like to subscribe to iamdave's list?"

Hrm. I think you've given me something fun to spend my weekend on

Should you make some progress post back here, please.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#183
post #52

Unfortunately, this still has the key flaw that has plagued outbound firewalls since their invention: "Currently, LuLu only supports rules at the 'process level', meaning a process (or application) is either allowed to connect to the network or not. As is the case with other firewalls, this also means that if a legitimate (allowed) process is abused by malicious code to perform network actions, this will be allowed."…

> In other words, it won't stop malicious Javascript running in your browser from making an outbound connection, which is the most common way for malware to do that. This might be possible, if you start off with deny-all as the default and then start manually adding exceptions as you browse.

and how does one verify the new exception request is trustworthy. it's enough to drive one mad the whole cat/mouse game of trust/deny. the only winning move is not to play.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#184

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

[deleted]

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#185

What I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run to…

Pihole is your best friend.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#186
post #152

Earlier quoted context omitted.

I handle this for my whole network with a pi-hole[0]. [0] https://pi-hole.net

When I tried pi-hole I was amazed by it. Until the day I discovered someone in China hacked it :-///

Sounds like a poor or reused password.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#187
Windows WARNING:

If you plan on doing same thing in windows be aware you need to disable Dnscache service. Its impossible in windows to screen loopback network interface, means you cant filter which programs get DNS access while "DNS Client" is running, its all or nothing. DNS is a very popular covert exfiltration channel.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#188

Earlier quoted context omitted.

It’s the charge for upgrades that I don’t like. I bought it once, upgrades should be free. Or so significant that I want to pay.

Show me this universe where programmers don’t have to eat after their 1.0!

It depends... If I'm paying for an update that fixes bugs/issues released in a prior version then I don't expect to pay for that.

If the new version has a lot of new features I would be OK paying for that.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#189
post #151

Earlier quoted context omitted.

>I happily paid for Little Snitch and was comforted by the fact that I was the customer. I paid for it, too. But then the upgrades went from complimentary to paid, and I bailed.

The new major version offers a lot more functionality. I looked into it and decided I wanted it, so I upgraded. I assume that I could have stayed with the old major version but I'm not sure.

With High Sierra you couldn't, the previous version doesn't work on it.

Re: LuLu: An open-source macOS firewall that blocks unknown outgoing connections

#190

Earlier quoted context omitted.

It’s the charge for upgrades that I don’t like. I bought it once, upgrades should be free. Or so significant that I want to pay.

you only need to pay every 3-5 years aaaaand only if you want to upgrade, aaaaaaand you can keep using your last updated version, aaaand only 50% of the full price

You can't, if you also want to upgrade your OS. v3 doesn't work on High Sierra.
Post reply on HN