macOS Free and Open-Source Security Tools by Objective-See
objective-see.org
objective-see.org
Personally I'm not comfortable with this due to the level of access they require and thought it worth to mention.
https://github.com/objective-see/LuLu/blob/dfe48c2a0f7a86361...
It does seem like a good idea that this could be disabled but now it's hard coded.
Issue on the topic: https://github.com/objective-see/LuLu/issues/488
> I will look into why Sentry.io is being contacted so often! This is strange as unless they changed their SDK/framework, is only supposed to happen on a crash report.
1: https://github.com/objective-see/LuLu/issues/488#issuecommen...Just to be clear I have no ill will towards this developer or their products.
Crash dumps can contain highly sensitive info. I have blocked Crashlytics[0] and Sentry with my pi-hole so nothing gets sent. I'm starting to believe these tools are abused and not even used to improve services. They're basically a MITM so people can violate other's privacy.
edit: it looks like it is working, but unknown if there are any negative side-effects at this point.
└─[$] <> ping sentry.io
PING sentry.io (0.0.0.0): 56 data bytes
ping: sendto: Socket is not connected
ping: sendto: Socket is not connected
Request timeout for icmp_seq 0
^C
--- sentry.io ping statistics ---
2 packets transmitted, 0 packets received, 100.0% packet lossNow I have to edit that same message and mention that LuLu also phones home to sentry. Can't blame people for wanting stack traces but wow it's a tricky subject in terms of privacy.
I've been using Shortcat for years, and I thought it was long since abandoned. I was even more surprised to see a new version was released last month. I seriously stopped checking on this project years ago, and just kept a backup .dmg.
I am sad to read about sending out info to Sentry, but I guess that is something I am going to have to think about some more.
lulu is not nearly as polished as hands off! (may it rest in peace) or little snitch, but it gets the job done. i also have some rules in pf (via murus gui) to block things like google and facebook on a system-wide level.
Software that exfiltrates your usage, crashes, or other data from your own machine without advance, opt-in, informed consent is unethical and disrespectful.
Heh, I C what you did there.
Last i tried LuLu it worked similar to Littlesnitch, though nowhere near as "polished". The basic functionality is more or less the same though, with Littlesnitch offering to automatically unblock known "trusted" services like Apples own services.
> And is it even useful anymore with macOS being increasingly locked down
It's an application firewall, so even if MacOS is locked down, any app can still roam freely (within it's jail). Suppose some app has access to your contacts, that means it can still upload every contact to a server, and an application firewall can help you detect/block that.
Even if you don't use iCloud, the App Store, iMessage, FaceTime, or any of it - macs still send tons of realtime usage data to Apple even if you don't want them to.
I once found out that a VPN that I have uninstalled long time ago still has shady entry in the login items thanks to KnockKnock.
Some of the tools are still useful to have installed though.
When I first installed it, it required quite some efforts to consciously filter/allow traffic from/to for the apps. By the time, all regular apps were properly configured for the rules and now I see notifications for block/allow only when there is uncertain traffic going out.
Definitely recommend to give it a try.
Discussions: https://hn.algolia.com/?q=nirsoft
On Linux, I use OpenSnitch. The name's based on LittleSnitch. Its a layer 7 firewall. Quite polished these days.
1. when our "browsing, and information self-exposure" tools are better (automatic note taking parrot robot that sits on your shoulder and remembers everything you've seen so you don't have to) and
2. when our Internet's base concepts are more equitable to content creators/intellectual property owners.
More:
For number one, obviously it's handy if you're interested in a website to be reminded of that website latest and greatest successes.
Number two, with the Lamina1 news recently it's got me thinking again about the inequitable economy of providing useful advances and information for free, or in this case tools, and then not being respected by the world in a way which the pressures of reality direct you to collapse or shut down your fantastic enterprise .. again in this case of creating macos anti-malware tools.
(Social comment: I see identifying a UX problem is one step in responding to someone's work, and the ramification of talking about your frustration is another. There's at least one more you can do, call to action: how would you, Message Poster with the beef against that UX, have offered to solve, or make better, these problems responsibly if you were the owner of the website?)
Showing me a newsletter signup before I've read the content implies that I'm interested in getting more of what I expect the content will be about, not what it actually is. Asking me to sign up for more interesting sounding titles before I've even had a chance to decide if I enjoy the content within implies that you, the content author, don't actually care if I enjoyed the content. What you're most interested in is pushing more clickbait titles in my face.
Put a newsletter sign up button near the end of the content, or in a side bar next to the content- anywhere that makes it seem like I'll get more of the content I am enjoying.