18 ms·
LuLu: An open-source macOS firewall that blocks unknown outgoing connections
- reaperducer 9y agoLooks promising. I used to use Little Snitch, but last year they decided to charge for the new version, and I uninstalled it. Little Snitch was effective, but overly complex for the average user. I'm sure it's great for someone who configures networks on a regular basis, but as a Mac user, I just want to use my Mac. If I wanted to twiddle with security settings all day long, I'd still be on Windows. This looks like it might be a good, simple, replacement. Hopefully as it evolves it doesn't get swamped by feature bloat.
- simplify 9y agoI've gladly paid for Little Snitch twice. OS X attempts so many random connections now I don't know what I'd do without it.
- ballenf 9y agoThat comment makes me chuckle. These days, I have close to zero faith in commercial software that is "free", assuming that the business model is selling my data. I happily paid for Little Snitch and was comforted by the fact that I was the customer.
- craftyguy 9y agoNothing prevents companies that sell you proprietary software from also selling your data.
- coding123 9y agoWell I'm assuming things like this helps: We do not share nor sell your data. https://www.obdev.at/privacy-policy.html https://www.obdev.at/privacy-policy.html However you may be referring to the same notion that nothing stops someone from murdering someone else.
- vezycash 9y agoUntil the company is acquired. And then the disclaimer disappears silently.
- inopinatus 9y agoOutcomes from such clauses also hinge on whether metadata describing the operation of their system - such as logs showing who communicated with who - is your data, or their data. Following recent changes to law here in Australia, for example, metadata is essentially the property of the state.
- staunch 9y agoTrue. But in practice, a software company that's making money from users has a lot of incentive not to harm their brand, or open themselves up to competition, by being shady. It does happen but users are waking up to the problem and companies are learning.
- icelancer 9y agoThis comment makes me chuckle. The idea that since you pay for something means that the company won't sell your data.
- coding123 9y agohttps://www.obdev.at/privacy-policy.html https://www.obdev.at/privacy-policy.html
- matthewmacleod 9y agoIt doesn’t guarantee it, no. But it does mean that there are fewer incentives in place to do so.
- ballenf 9y agoI didn't mean to mock the sentiment and you're absolutely right to take a very cynical approach these days to any privacy promises.
- guelo 9y agoIndeed. I'm especially suspicious of "security" software. Releasing free high quality security seems to be a popular attack vector for advertisers, spammers, hackers, and nation states.
- reaperducer 9y ago>I happily paid for Little Snitch and was comforted by the fact that I was the customer. I paid for it, too. But then the upgrades went from complimentary to paid, and I bailed.
- hesk 9y agoThe new major version offers a lot more functionality. I looked into it and decided I wanted it, so I upgraded. I assume that I could have stayed with the old major version but I'm not sure.
- pilsetnieks 9y agoWith High Sierra you couldn't, the previous version doesn't work on it.
- Udo_Schmitz 9y ago3.8.2 works with High Sierra
- paulie_a 9y agoThat is the traditional business model of software
- chisleu 9y agoI paid for the old version. I like it. I think they only charge for the new microphone / camera portions of the new version.
- keyboardmonkey 9y agooh dear, LittleSnitch wanted to charge money for creating a really handy tool, how terrible.
- prepend 9y agoIt’s the charge for upgrades that I don’t like. I bought it once, upgrades should be free. Or so significant that I want to pay.
- zarify 9y agoConsidering Apple's constant shifting of goalposts with macOS, what counts as "significant" in your book, even disregarding user-facing features? And how significant is the ~$50 they want for it?
- always_good 9y agoIt's just $25 for an upgrade. I have to roll my eyes at someone who scoffs at a $25 upgrade every few years. If they're not cool with funding any future development on the product, then they must be cool with not upgrading. But of course they instead entitle themselves to all of your future labor because they once threw some shekels your way.
- deleted 9y ago[deleted]
- vim_wannabe 9y agoNow we just need to figure out who pays for those upgrades. I think we could try a scheme where we keep growing the user base so more recent customers pay for the prior customers' upgrades. Hmm, wait a minute...
- sudouser 9y agosounds nice, i'm in, now i'm get some people under this not-a-pyramid
- ComputerGuru 9y agoFor those on Windows, http://www.sphinx-soft.com/Vista/index.html http://www.sphinx-soft.com/Vista/index.html does the same using the native firewall (so no 3rd party dependencies, services, or bloat) (though they've ~recently added paid licenses with more features to their basic offering). I only wish it were cleaner and simpler. I don't think the Windows Firewall API is too bad, I should add this to my bucket list of open source software to write that I'll maybe get around to in the next 20 years....
- stryk 9y agoThanks for the link. I'm curious how it compares to https://www.binisoft.org/wfc.php https://www.binisoft.org/wfc.php although this looks to be free I don't think it's open source. Not having much luck finding license info for it.
- hendersoon 9y agoI have not used Simplewall but I am a paid customer of Binisoft WFC and do recommend it. WFC works great and is frequently upgraded, the developer is very responsive to his users. It does have a crude ugly UI, so just don't expect it to look like Little Snitch (which I also endorse on MacOS) or Glasswire.
- mandelbulb 9y agoAs you can see in the feature comparison[1], the free edition doesn't cover Windows' system applications, it doesn't offer a lot of pre-defined rule sets, or Desktop integration. Binsoft's WFC does. However, if you're willing to spend money, Sphinx's product seems to offer quite a bit more features, but then you might as well consider other products out there. Also, Binsoft's WFC UI, especially that of the rules editor, slowed down for me pretty heavily with just a hundred rules. I'm not sure how Sphinx W10FC handles it but the Binsoft WFC doesn't accept not pre-defined file types. So if you have a binary with a random suffix, like anti-cheating rootkits often do, you can only add a generic allow or deny rule. You can't configure the rule. [1] http://www.sphinx-soft.com/Vista/order.html http://www.sphinx-soft.com/Vista/order.html
- 9y ago
- blocked_again 9y agoLuLu is a billion dollar hypermarket chain. I think it would be a good idea to rename this project in the beginning if you don't want to get into any copyright issues. https://en.wikipedia.org/wiki/Lulu_Hypermarket https://en.wikipedia.org/wiki/Lulu_Hypermarket
- a_t48 9y agoDoesn't that only apply if they are competing businesses?
- deleted 9y ago[deleted]
- guan 9y agoMany countries have a “well-known trademark” doctrine where a mark can be so famous that any business using it could be a source of consumer confusion. For example, if you see that Coca-Cola has released a firewall, you might well think it has some connection to Coca-Cola, even if you know they are not currently in the software business. Lulu supermarket may not be well known enough to enjoy that kind of protection.
- reaperducer 9y agoSometimes they can be the same business in different markets and use the same trademark. Think about how many cities have "Great Wall" Chinese restaurants. Most people only know trademarks at a national level. In the United States, at least, each state can grant its own trademarks. I've done it in Illinois ($50/10 years), and Texas ($10/10 years).
- jtokoph 9y agoCan't a retail chain and a firewall can share the same name without issues?
- Ninn 9y agoApple and Honda can, I would be suprised if not Lulu too can...
- calebm 9y agoVery cool! So this is an open-source Little Snitch then?
- devin 9y agoCertainly looks that way
- stryk 9y agoI'm not personally a mac user, but I'm still very glad to see projects like this being developed as open source. Very cool I hope this goes on to be a really solid piece of software. Does anybody have any recommendations for good ways to get fine-tuned control of Windows' default firewall?
- deleted 9y ago[deleted]
- erAck 9y agoNowadays it's more important to control and restrict outgoing connections than incoming connections. Who would had thought of that 25 years ago.
- craftyguy 9y ago> Who would had thought of that 25 years ago. Maybe that's why this problem exists now, because no one had thought of it?
- draugadrotten 9y agoGive it another 25, and you will have to pay a premium for things which are stand-alone, disconnected from the net. Want a car which is not navigating using cloud AI? Only the rich can afford that...
- rubicon33 9y ago> Want a car which is not navigating using cloud AI? Only the rich can afford that... Good. I sure hope only a small fraction of the population will be able to manually drive their car in the future. It would save lives, time, and money for everyone if the bulk of the idiots were unable to manually drive their car.
- nxc18 9y agoI interpreted the alternative to that being locally run AI, which is not implicitly spying on you and capable of doing nefarious things (e.g. not allowing you to navigate until you pay this month’s upgrade fee).
- TeMPOraL 9y agoI assumed the same, too. A self-driving car should be able to navigate itself without an Internet connection; any permanent ties to the cloud are just anticonsumer business strategy.
- reaperducer 9y ago
- doctoboggan 9y agoDoes anyone know how this compares to Little Snitch?
- 333c 9y agoInstalled, tried to git clone https://some.url/repo which hung and didn't show any sort of prompt from LuLu. I imagine (thought I haven't used it) that Little Snitch would prompt to allow/deny git from connecting to the network. So, it doesn't seem very functional, but it is an alpha, so that is likely expected.
- skue 9y agoBased only on glancing through the linked product page... here are some LS features LuLu currently lacks: * Reporting domain names rather than just reporting destination IPs. * Inbound monitoring & rules * Temporary rules that auto-expire (e.g. Once, next 15 mins, etc.) * Fine-grained control over protocol/domain/subdomain in blocking rules (at least when prompted) * Graphical monitor of recent blocked/allowed traffic * Profiles to easily change rule sets based on network, etc. * Unclear whether LuLu provides special handling of connection attempts during startup, software updates, etc. * Graphical installer, polish, support, etc. ...OTOH, LuLu does provide features I don’t recall seeing in LS: * Icon indicating whether originating binary has been signed by system/third party/unsigned * Button to optionally check binary hash against VirusTotal
- 333c 9y agoThe install page says that `sudo configure.sh -install` is the install command. The command is actually `sudo ./configure.sh -install`. Further, it should probably be `sudo ./configure.sh --install` (with two hyphens), as is convention for named (edit: long-form) options on the command line.
- craftyguy 9y ago> as is convention for named options on the command line. Gosh, I really wish that people would follow a convention for named options on the command line. I don't even really care which one, as long as they were all consistent in picking one.
- reaperducer 9y agoI've seen /, -, --, and +. Any other ones leap to mind? I wonder if there's a complete list somewhere.
- pash 9y agoThe usual convention is a single hyphen for short-form (single-letter) options, and a double hyphen for long-form options: > python -v or > python —-version It’s good practice to offer both. It should also be possible to set multiple options at once by appending one after another in short form following a single hyphen: > ls -alR is the same as > ls -a -l -R Long-form options are technically a GNU thing [0] and are not mentioned in the POSIX standard, but they’re conventional enough now that I think it’s good practice to include them in any CLI program. There are also a number of looser conventions about the meaning of certain short-form options [1]. 0. https://www.gnu.org/prep/standards/html_node/Command_002dLine-Interfaces.html https://www.gnu.org/prep/standards/html_node/Command_002dLin... 1. http://www.catb.org/esr/writings/taoup/html/ch10s05.html http://www.catb.org/esr/writings/taoup/html/ch10s05.html
- 333c 9y agoThanks, this is what I meant in my original comment. I said "named" when I really meant "long-form," as you said.
- kozhevnikov 9y agoIt's on Homebrew as a Cask brew cask install lulu
- galonk 9y agoSo even open source projects are doing that thing where they immediately cover the page you're trying to read with an annoying spam box?
- reaperducer 9y agoWasn't there a note form the Google search team not too long ago that they were going to demote sites that use the splash divs? How do I know if I want to sign up for your newsletter if I haven't been able to look at your site yet?
- throwacide 9y agoUnless I’m using it wrong it doesn’t support individual connections in apps like chrome. How is this useful if apps like chrome are either on or off? Also can’t do anything in bulk.
- kristofferR 9y agoWhat's the CPU usage? I tried Little Snitch, but it was often consuming insane amounts of CPU (40%+) which matters a lot on a 12' Macbook on battery, so I uninstalled it.
- killjoywashere 9y agoLong time Little Snitch user here, that seems ... high
- kristofferR 9y agoYeah, I though so too. I even tried a complete reinstall, but that didn't improve the situation. It's probably due to the absurd amounts of logging it does (every single connection tracked on a world map), which I didn't find a way to disable... I probably have an abnormal number of connections too due to torrenting (only Linux distros obviously). The Macbook CPU isn't high performance either.
- kstrauser 9y agoMy "Little Snitch *" processes have used a total of 10 minutes of CPU time since my last reboot. I'd ask their support about this.
- pdonis 9y agoUnfortunately, this still has the key flaw that has plagued outbound firewalls since their invention: "Currently, LuLu only supports rules at the 'process level', meaning a process (or application) is either allowed to connect to the network or not. As is the case with other firewalls, this also means that if a legitimate (allowed) process is abused by malicious code to perform network actions, this will be allowed." In other words, it won't stop malicious Javascript running in your browser from making an outbound connection, which is the most common way for malware to do that. It does say "currently", but I'm not sure how you would get around this flaw; at any rate, nobody has yet figured out how.
- ballenf 9y agoCombining process (source) and destination rule combos, the Little Snitch could be customized to "solve" this issue. Process A is allowed to talk to domains X, Y and Z. "Solve" not solve because, for me, setting up baseline rule sets was too intrusive to my workflow.
- pdonis 9y ago> Combining process (source) and destination rule combos, the Little Snitch could be customized to "solve" this issue. Process A is allowed to talk to domains X, Y and Z. Ok, and what happens when I want to browse to a different site? >for me, setting up baseline rule sets was too intrusive to my workflow It seems like that would be true for anyone that wants to use their browser to go to more than a small number of websites.
- qubex 9y agoAnd of course, anything local to the machine can only be trusted as long as you are willing to accept that the kernel is not compromised, because it's pretty trivial for a rootkit that is running in the kernel’s context to conceal files, sockets, or even create unreported network interfaces. I remember that Greg Hoglund's rootkit.com contained several first crude (and not so crude) implementations that could do this kind of things (FU springs to mind?) way back in the mid 2000s or thereabouts. The answer to that, of course, is that if you are really serious about firewalling, said firewall must be a separate device.
- jle17 9y agoUnless I'm mistaken, this isn't actually open source, as it's under a non-commercial clause. edit: there is an open issue about it: https://github.com/objective-see/LuLu/issues/4 https://github.com/objective-see/LuLu/issues/4
- ReverseCold 9y agoSo it is open source, but you're not free to do what you want with it.
- jle17 9y agoNon-commercial clauses are explicitly prohibited by the OSD.
- davefp 9y agoLink for the lazy: https://opensource.org/definition https://opensource.org/definition
- chisleu 9y agoopen-source != Open Source open-source == source code is open Open Source == licensed compliant with the OSI's OSD right?
- vertex-four 9y agoNo, I'd say that your "open source" is either "shared source" or "source available" - depending on exact terms - using terms that we've been using for a couple of decades now.
- jle17 9y agoAre you seriously arguing that you can arbitrarily change the meaning of well understood words simply by adding a dash to them ?
- 9y ago
- joeblau 9y agoThis project looks awesome. I just looked at the code and it looks like every line of code has a comment. It seems like a bit of overkill in Obj-C being such a verbose language. Aside from that, I'm definitely going to check this out.
- killjoywashere 9y agoWhat I want for all these services (Little Snitch, ESET, etc) is an EasyList-like ... list. A community-aggregated and reviewed list of servers that don't merit my connection. I'd pay a monthly subscription fee for that. I'd also like separate lists for * "this wifi is public, be extra cautious" * "this wifi is public, be nice and don't torrent, do backups, etc" * "I'm on a metered connection (e.g. LTE), don't run torrents, backups, etc" edit: for anyone looking for a monetizable idea: this post has 41, no 42, no 43 points in about an hour. Probably a good idea...
- lifty 9y agoI would pay for such a service as well. In addition to that, I would love if this service would allow companies like Apple and Google to maintains their own lists of IP's and update them regularly, so you can be 100% sure that an IP belongs to them.
- killjoywashere 9y agoperfect seed material for the list. Start from an empty Little Snitch config and whois everything that tries to connect.
- igravious 9y agoIs that not somehow auto-discoverable using DNS trickery?
- uxp 9y agoNot entirely. From what I understand, these outbound firewalls are working at the kernel level and interject themselves into a network connection outside of the DNS lookup process. You could reverse-dns lookup the IP, which Little Snitch tries, but with things like CDNs and AWS EC2, you end up with a lot of reports of applications trying to connect to "foo.akamai.com" OR bar.akamai.com", where foo and bar are entirely separate entities, or just simply to ec2-0.1.2.3.aws.amazonaws.com or what-have-you. Little Snitch appears to maintain it's own cache of DNS entries as well, so if you've got one application that connects to some CDN's IP via it's own CNAME, many times other applications will appear to be connecting to the first application's CNAME when they attempt to connect to the same IP because LS has resolved that IP to the first CNAME more times, or first, or something like that. It's not perfect, and frequently it isn't even helpful.
- endlessvoid94 9y agoDumb question: is something about OS X’s built in firewall that’s insufficient? Always love new projects like this, just curious though.
- skue 9y agoIn the FAQ, bottom of page: > Do I need LuLu if I've turned on the built-in macOS firewall? > Yes! Apple's built-in firewall only blocks incoming connections. LuLu is designed to detect and block outgoing connections, such as those generated by malware when the malware attempts to connect to it's command & control server for tasking, or exfiltrates data.
- endlessvoid94 9y agoThanks!
- petee 9y agoConfusing, since they use the PF filter, you can absolutely block outgoing connections, atleast by port, app or user
- chisleu 9y agoIs the author associated with CrowdStrike? I noticed he/she was using FancyBear
- chisleu 9y agoWhy downvote a legit question on topic? The term FancyBear came from the cofounder of crowdstrike: Dmitri Alperovitch. http://www.esquire.com/news-politics/a49902/the-russian-emigre-leading-the-fight-to-protect-america/ http://www.esquire.com/news-politics/a49902/the-russian-emig...
- nikolay 9y agoI've been using all Objective See projects, but I have issues with: - stability - often their tools have memory leaks; - consistent UX - each tool looks and behaves differently; - stacking of dialogs - often by the time I click, a new popup replaces the old one, and I approve something I don't even get a chance to see!
- DavideNL 9y agoYou should report the problems to the Developer, he's very responsive...
- kstrauser 9y agoFirst, this is awesome. Thank you! Second, is the business model of Objective-See to offer open source alternatives for Objective Development's products (LuLu instead of Little Snitch; OverSight instead of Micro Snitch)?
- bringtheaction 9y ago> This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License. Weird choice of license.
- cheeze 9y agoAs someone unfamiliair, what is weird about the choice?
- hoistbypetard 9y agoThe people who developed the creative commons licenses recommend against using them for software. [From their FAQ](https://creativecommons.org/faq/#can-i-apply-a-creative-commons-license-to-software https://creativecommons.org/faq/#can-i-apply-a-creative-comm...): > We recommend against using Creative Commons licenses for software. Instead, we strongly encourage you to use one of the very good software licenses which are already available. We recommend considering licenses made available by the Free Software Foundation or listed as “open source” by the Open Source Initiative.
- torstenvl 9y agoThat's because we treat software very differently from most other content subject to copyright. As in this case, (reading the above threads) there's confusion as to the no commercial use clause extends to the content or the outcome of its processes. That is to say, NoCommercialUse for a book clearly means for derivative works. Nobody would ever suggest you can't read a book while in a commercial establishment. But in software we routinely place use restrictions on the end-user. Kind of bizarre, when you think about it.
- hoistbypetard 9y agoI completely agree with your first sentence. But I think your interpretation of NonCommercial is a bit off. NonCommercial in the context of a book does not refer to "using" the book or to creating derivatives. You don't need a license to read a book. Rather, it refers to copying the book. They have a separate clause that refers to creating derivative works from the book. If you have a CC-BY-NC book, that means you're allowed to copy the book as much as you want as long as it's not for commercial purposes. If you have a CC-BY book, that means you can copy it as much as you want, even if it's for commercial purposes. If you have CC-BY-ND, that means even though you can copy the book as much as you want, even for commercial purposes, the author is not granting you the right to make derivatives. Software is different because copying software is a necessary part of using it. So CC-BY-NC for software could quite reasonably be read to restrict its use in a commercial environment because you (notionally) need a license to make that copy from the internet to your hard drive, and from your hard drive to system RAM so that you can use it.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- viach 9y agoAre you sure it won't interfere with required system connections? Like updates etc, all this boring stuff Mac users tied to?
- danjoc 9y agoFalse advertising. Nothing can stop an AMT process running in ring -3.
- omidraha 9y agoI need something like this for Ubuntu
- nthompson 9y agoReally cool tool thanks! One problem to maybe take care of next iteration: $ top -o cpu LuluDaemon 29.5%
- Abishek_Muthian 9y agoThe author is not subtle in letting know that this is intended to be open source replacement for Little Snitch (domain!). But at-least macOS has little snitch, closest for Linux was opensnitch which was announced on HN few months back - https://github.com/evilsocket/opensnitch/ https://github.com/evilsocket/opensnitch/ but I'm not sure whether it's actively being developed though.
- adisbladis 9y agoNo sadly Opensnitch is dead. Evilsocket for whatever reason went back to OSX and I (who was the other large contributor) did not feel the motivation to work on the project anymore.
- Abishek_Muthian 9y agoThat's unfortunate. Do you think it'll be worth the effort to port the LuLu base to Linux platform?
- bmaupin 9y agoDouane[0] is another application firewall for Linux that's still active as far as I can tell. [0] http://douaneapp.com/ http://douaneapp.com/
- Abishek_Muthian 9y agoYes, but package managers for it for non debian based distro's are bit of a mess.
- rasz 9y agoWindows WARNING: If you plan on doing same thing in windows be aware you need to disable Dnscache service. Its impossible in windows to screen loopback network interface, means you cant filter which programs get DNS access while "DNS Client" is running, its all or nothing. DNS is a very popular covert exfiltration channel.
- vesche 9y agoPlease remove the popup email signup.
- zipotm 9y agosudo ./configure.sh -install
- Khaine 9y agoIf you are looking to block IP addresses, you can always use pf. Its built into macOS. It does require some command line knowledge.
- deleted 9y ago[deleted]
- casca 9y agoIt's good to see another option for an outbound firewall, but as an industry we still have a long way to go. As with many security solutions, there is a conflict between flexibility and usability. I want: 1) To be able to choose the exact host/subnet/domain that an application can access with a good UX 2) Have someone else curate a list that I subscribe to that handles most cases 3) Work on desktop and mobile For choosing the exact host/subnet/domain on a per-application basis, the best UX I've seen on any platform is FirewallIP[1], the unmaintained software on a jailbroken iPhone. So many desktop solutions[2] only let you choose Allow everything or Deny everything, Little Snitch and Windows 10 Firewall Control[3] are exceptions, but even they are limited. The curated list option should be easy enough to support on most platforms. Easylist has shown how well it can work on the browser when combined with uBlock Origin. Install it for someone who is technically naive and they'll just see no ads with no negative experience. The mobile platform is harder to support as under Android you need to root the phone to get access to the underlying iptables firewall with something like Afwall+, or you run a fake VPN back to the device and filter there which is prone to failure (is it working? has it stopped itself for some reason) and has less flexibility. Under unjailbroken IOS, products like Surge, Potatso2 and Shadowrocket run a local proxy that is similar to the fake VPN under Android, but requires manually editing a text file for configuration and seem to be designed to get around the Chinese internet restrictions rather than privacy. [1] http://r-rill.net/FirewalliP7/FiPDepiction.html http://r-rill.net/FirewalliP7/FiPDepiction.html [2] Glasswire on Windows, Douane and OpenSnitch on Linux, AFwall+ on Android [3] http://www.sphinx-soft.com/Vista/index.html http://www.sphinx-soft.com/Vista/index.html
- fishmeat 9y agoWhy does macOS need this? (Asking because I'm not a mac user)
- Asmod4n 9y agoBreaks networking on High Sierra. No Browser works anymore. curl stops working. git doesn't even trigger its asking window. Power usage doubles when networking is used too. After uninstalling it the kernel crashes. Sad.
- tuananh 9y agohas anyone tried both Hands Off[0] and Little Snitch? How is Hands Off compared to LS? Also: Radio Silence[1]? [0]: https://www.oneperiodic.com/products/handsoff/ https://www.oneperiodic.com/products/handsoff/ [1]: https://radiosilenceapp.com/ https://radiosilenceapp.com/