Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Why no passive-block mode? #621

Open
POMATu opened this issue Jul 9, 2024 · 4 comments
Open

Why no passive-block mode? #621

POMATu opened this issue Jul 9, 2024 · 4 comments

Comments

@POMATu
Copy link

POMATu commented Jul 9, 2024

There is only passive-allow mode for some reason which probably makes sense if you just wanna limit certain apps, but i want to limit all apps except the ones i am using
and i dont want to allow apple stuff to go to internet which makes windows pop up every now and then there is no end for apple's shit calling home

passive-block mode would be very convenient in this case

@objective-see
Copy link
Owner

Interesting.
Just to double check, the logic would be?

  1. Silently apply existing rules
  2. New connections would be silently blocked (but no rules would be created)

@POMATu
Copy link
Author

POMATu commented Aug 26, 2024

  • Silently apply existing rules

  • New connections would be silently blocked (but no rules would be created)

yes, example of use case is pretty simple:

  1. Install macOS
  2. Install Firefox
  3. Only allow firefox to go to internet and maybe DNS too
  4. Install another app later and whitelist it too

Thats it, no any other bs needs to access internet:

image
image
image
image
image
image

after some time i got bored taking screenshots but it was like this for 10-20 boots maybe:
image

now its a bit more chill but still popping up sometimes, also my lulu configuration is bloated with a lot of deny profiles for the apps that i dont even know what they are doing because i had to press block to shut it up on each popup. So yh LuLu does not have whitelist mode at all at this point

And yes i am able to use macOS just fine like that (i am not using any apple services). As a bonus my airpods are not allowed to do firmware update without my consent too

objective-see added a commit that referenced this issue Aug 27, 2024
@objective-see
Copy link
Owner

Thanks for the additional information, yes ok, that makes a lot of sense. Will be in (soon to be released) next version:

image

@objective-see
Copy link
Owner

Will be added in v3.0, though the pre-release now already has this:
Screenshot 2024-09-16 at 17 35 07

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants