3 ms·
Does anyone know of any good firewalls for macOS? The built in firewall is practically unusable, and if client isolation can be bypassed, the local firewall is
by madjam002 7mo ago
Does anyone know of any good firewalls for macOS? The built in firewall is practically unusable, and if client isolation can be bypassed, the local firewall is more important than ever.
I often have a dev server running bound to 0.0.0.0 as it makes debugging easy at home on the LAN, but then if I connect to a public WiFi I want to know that I am secure and the ports are closed. "Block all incoming connections" on macOS has failed me before when I've tested it.
- runjake 7mo agoLittle Snitch is probably the most popular one, written my devs who deeply understand macOS firewall architecture. https://obdev.at/products/littlesnitch/index.html https://obdev.at/products/littlesnitch/index.html
- mrexcess 7mo agoLittle Snitch is commercial. If you want largely similar features (focused on egress), check out LuLu: https://github.com/objective-see/LuLu https://github.com/objective-see/LuLu
- runjake 7mo ago+1 Thanks, I forgot about LuLu!
- ProllyInfamous 7mo agoLittle Snitch is a user-friendly, software-level blocker, only – use with caution. Just FYI: LittleSnitch pre-resolves DNS entries BEFORE you click `Accept/Deny`, if you care & understand this potential security issue. Your upstream provider still knows whether you denied a query. Easily verifiable with a PiHole (&c). I liken the comparison to disk RAIDs: a RAID is not a true backup; LittleSnitch is not a true firewall. You need isolated hardware for true inbound/outbound protection.
- gruez 7mo ago>Just FYI: LittleSnitch pre-resolves DNS entries BEFORE you click `Accept/Deny`, if you care & understand this potential security issue. Your upstream provider still knows whether you denied a query. Easily verifiable with a PiHole (&c). This also feels like an exfil route? Are DNS queries (no tcp connect) logged/blocked?
- ProllyInfamous 7mo ago>Are DNS queries blocked? No, not with LittleSnitch (neither in/out-bound). When you see the LittleSnitch dialogue (asking to `Accept/Deny`), whatever hostname is there has already been pre-resolved by upstream DNS provider (does not matter which option you select). This software pares well with a PiHole (for easy layperson installs), but even then is insufficient for OP's attack.
- tiger3 7mo agoLittleSnitch
- roflchoppa 7mo agohttps://objective-see.org/products/lulu.html https://objective-see.org/products/lulu.html