14 ms·
Little Snitch 3 – Protect your privacy
- watersb 10y agoFWIW, I love Little Snitch and have used it for at least ten years.
- diggan 10y agoWhy are OSX applications in general so bad at telling website users which platforms they support? Like always, I have to keep digging around in the website, just to find out that it only runs on OSX... Does anyone know a similar utility for Ubuntu/Linux systems? Paid or free, doesn't matter.
- deleted 10y ago[deleted]
- matthewmacleod 10y agoI'd argue it's sort of… insanely clear, when clicking on the download page, that there is no version available.
- dazc 10y agoYou are right but it's likely most people wasted a few minutes reading about it before discovering this?
- win_ini 10y agoAh, the price of Running Ubuntu/OSX/Windows....it always bites you in the ass. This is like the B2B SaaS marketspace - it's almost taken for granted that your app integrates with Salesforce. People are surprised if it isn't. However, anyone who runs, Microsoft CRM, SugarCRM, Netsuite, etc. - are all used to hearing "Sorry, we don't integrate with X". I'd say ubuntu falls into a similar category....
- saberworks 10y agoI disagree. There are a lot of sites out there that detect your OS and only show you downloads appropriate for your platform.
- bisby 10y agoI dont click download links until I understand what the product is. It's disappointing to spend time learning about a product and THEN finding out I can't use it. It should be front and center, or have a logo big enough that a quick full length page scroll will show at an instant the platforms available without having to read. https://obsproject.com/ https://obsproject.com/ clearly shows it is cross platform. https://adium.im/about/ https://adium.im/about/ clearly shows that it is not.
- chillacy 10y agoI almost wonder if shortsighted optimization of the sales funnel encourages not putting the platform up front since that would drive people away (who wouldn't buy the app anyways, but that's not always apparent). Either way it didn't cost the website owner much to lead on some people not in their target audience.
- ancarda 10y agoPerhaps they thought the screenshots made it clear enough; like this one: https://www.obdev.at/Images//littlesnitch/index/alert_on_screen.png https://www.obdev.at/Images//littlesnitch/index/alert_on_scr... shows Little Snitch blocking iTunes (with an Aqua-styled UI). Although I'll admit it doesn't mention what OS or what version except a small line on the downloads page: Runs on OS X Yosemite (10.10) and later, including macOS Sierra (10.12).
- bisby 10y agoA screenshot demonstrates a place where it CAN run (and potentially where the devs run it), but doesn't EXCLUDE anything. You see screenshots of windows programs all the time with just a sidenote somewhere that is like "oh yeah, and for linux and mac too"
- hmage 10y agoNot to be biased, but personal 9 years of experience tell me that if a program has a landing page "oh yeah, and for linux and mac too", it looks shit on mac.
- justin_oaks 10y agoPlenty of apps look like shit but run just fine. Perhaps others don't share this view but I don't care so much how it looks if it gets the job done, especially if there is no other alternative.
- bisby 10y agoThat was an exaggeration, but many times programs that look identical (aside from window frames) across platforms don't show the window frames for every platform. Electron apps (for as unpopular as they may be) are pretty platform agnostic. If they show it on windows and just have a linux/mac download button its not a big deal. skype.com probably fits the bill of looks shit, but it shows android and windows 10 screenshots only. obsproject.com shows a lot of screenshots that look pretty windows 10-ish... but it also announces "Latest Releases <platform logos>" right at the top of the page. sublimetext.com shows windows only screenshots. And then mentions platforms at the bottom of the page. https://slack.com/is https://slack.com/is shows only mac screenshots. I imagine this reflects more on the developers than the actual product. Im pretty sure its available on other platforms. And my point was less about quality of programs, but availability. showing the window frame of a single OS does not mean that only that OS is available, sometimes that's just the only OS the marketing team uses.
- therealmarv 10y agoThe same can be said about Windows programs very often. And about your second question: ufw goes in that direction but is not exactly the same as Little Snitch.
- ComodoHacker 10y ago>ufw goes in that direction Which direction? Does it have [plans for] learning mode or even process-based rules?
- BHSPitMonkey 10y agoOutbound, as in you can regulate outbound connections originating from your apps.
- xd1936 10y agoCrossing my fingers that someone knows of an alternative for Linux, but my hunch is, it'll be some crazy iptables scripts or something :/
- therealmarv 10y agohttp://alternativeto.net/software/zone-alarm/?platform=linux http://alternativeto.net/software/zone-alarm/?platform=linux
- anc84 10y agoFirejail might be worth a try.
- blub 10y agoI was looking for such an app out of curiosity a while ago and found douanne. Never used it myself, but it was open source and had similar features.
- LordKano 10y agoThis looks promising.
- tornadoboy55 10y agoDouane Firewall
- nawtacawp 10y agoYes, I would buy a Linux version of this. I use UFW, but it requires a lot of work. A gui with that network monitor would be great.
- tornadoboy55 10y agoDouane Firewall
- tedmiston 10y agoLook at the download page — it's bolded: > Runs on OS X Yosemite (10.10) and later, including macOS Sierra (10.12).
- djsumdog 10y agoI don't run anything like this on my Linux box (just standard iptables), but I was looking for something like this for Windows a while back. The only thing I've really found is Windows 10 Firewall Control: http://sphinx-soft.com/Vista/order.html http://sphinx-soft.com/Vista/order.html It's nowhere near as nice as Little Snitch, plus it doesn't block the socket call and then allow it after you acknowledge it. The call will fail and the app has to retry the connection. Are there any better Windows solutions?
- rasz_pl 10y agotry Windows Firewall Control www.binisoft.org/wfc.php
- atomicUpdate 10y agoGlasswire looks pretty similar to this. I haven't tried the various paid versions, but even the free one shows a lot of useful stuff. https://www.glasswire.com/ https://www.glasswire.com/
- orionblastar 10y agoI use the free version on Windows 10. I haven't tried the paid version yet. I spend most of my time on Linux instead of Windows 10. It tells you when an app is updated, and when an app is making an Internet connection, and you can shut them off from the Internet if you wished.
- Keyframe 10y agoTiny Wall https://tinywall.pados.hu/ https://tinywall.pados.hu/
- andresgottlieb 10y agoWould they make more money if they let visitors from other platforms know it's a macOS app? No. That's why.
- beal 10y agoWould just take a little icon saying so. A lot of dev communities seem to be pretty ubiquitously mac these days. I wonder if it's a side effect.
- pfooti 10y agoYeah, I ended up visiting the site from my Linux machine just to find out if there was some kind of browser sniffing thing at work. Nope, osx only.
- 9935c101ab17a66 10y agoThe download page pretty explicitly states where it runs.
- Groxx 10y agoIt definitely goes both ways :) If anything I'd argue it's much more common for Windows apps to not specify Windows-only, because Windows has been the largest install-base for so long. And yeah. Annoys the heck out of me too, in both situations.
- DigitalJack 10y agoI run into this all the time with linux and windows.
- mattcoles 10y agoIs it open source? Couldn't find anything on their site which is disappointing.
- matthewmacleod 10y agoIt's not.
- middleclick 10y agoI realize that not everything can be made open source, but I personally don't trust closed source security applications.
- coldtea 10y agoWhat's to trust exactly? It blocks connections to domains/IPs you want it to, and allows others. You can easily verify that it behaves correctly with common network tools. This is not some deep cryptography shit...
- middleclick 10y agoWhat if it doesn't show a specific application making requests? What if it chooses to not do that? How do we know?
- coldtea 10y agoAs I said, "You can easily verify that it behaves correctly with common network tools". Track its behavior from an exit node of your network and see whether it matches your rules. Not really much difference than manually checking some tens of thousands of lines of an open source application, or trusting that the binary you got from the repo corresponds to the source (and of course even hashes can be tampered). Plus, even if it chose "to not show a specific application making requests" you'd still be blocking all others apps, and thus way better off than not having it installed.
- mattcoles 10y ago
- mellamoyo 10y agoAny similar software recommendations for Windows?
- Solsticea 10y agoGlasswire - https://www.glasswire.com/ https://www.glasswire.com/
- SippinLean 10y agoGlasswire is fantastic but the most useful features cost $50, FYI
- drdaeman 10y agoNope, it's quite different from Little Snitch. They're nice-looking, but don't have anything that even remotely resembles rules. All it can do is deny or allow all traffic, on per-application basis. If you want your email client to talk to only your email server but not anywhere else (as a security precaution) you'll have to use built-in Windows firewall facilities to set up such a rule. Rule management is coming in v2.0 - or so they say - but it's not yet here. --- Outpost Firewall used to be a powerful interactive firewall for Windows, but it's dead those days.
- mistermann 10y agoIs this similar? I installed it long ago and when looking at it, it didn't seem useful, but perhaps I am completely wrong?
- pidg 10y agoNot really anything that equals it, which is a surprise and a shame. The closest thing I've found is Net Limiter 4. https://www.netlimiter.com/ https://www.netlimiter.com/
- ing33k 10y agoZoneAlarm Firewall ?
- tetraodonpuffer 10y ago
- lwfitzgerald 10y agoI'm currently using LS, but one of the problems I have is that it doesn't support wildcard domain rules. This means ephemeral hosts quickly build up a large number of rules which soon become redundant.
- noja 10y agoYes it does. You click the domain in the popup an change it to the part of the domain you need. Then you view your invalid rules and it will show you which rules are no longer needed.
- noja 10y agoExcellent product, but needs some kind of rule sharing feature. There are so many network requests from different components that it can be overwhelming knowing what to allow.
- manmal 10y agoOr something like blacklists for known offender programs.
- mattkevan 10y agoDefinitely agree. I like the idea of it, but when I installed it for the first time and rebooted, it fired off so many confirmation requests for various cryptic services I had no idea what they were, I removed it just as soon as I'd managed to click through them all.
- tedmiston 10y agoIt definitely takes some time, effort, and research to get past this initial phase. In the future, I hope they explore more automation / semi-automation around system processes.
- kstrauser 10y agoLittle Snitch is noisy AF for the first day or so, but that's also kind of the point, right? You're running it because you want to know which apps are doing what. Those first sessions are enlightening. Wow, my laptop talks to all the things! That drops very quickly, though, as you tell it "yes, allow Slack to connect to" and "no, don't let Safari talk to sketchy.ru:8765". I still get the occasional popup, but now they're limited almost exclusively to newly installed apps that I'm running for the first time. That's still an eye-opener: no, I don't see a need for a calculator to connect to Google Analytics. Deny! Except for gamed, of course. There's no rhyme nor reason to which hosts and ports it wants to talk to. If you ever want to hack a Mac running Little Snitch, call your process "gamed" and the own will allow it through (if they haven't already set "allow connections to any host and port because alert fatigue lol").
- khana 10y ago
- iends 10y agoThose of you who own Little Snitch...do you regularly block outgoing connections from applications you regularly use?
- BugsJustFindMe 10y agoPeople do it for pirated copies of Adobe software because of how much it phones home. Do a quick google search and you'll find many sn/crack/warez (do people still use that word?) instructions talk about editing hosts files or installing Little Snitch.
- n1000 10y agoI do it even though I have legal copies of Microsoft Office and Adobe software. It is incredible how often these apps send around data even while I am not using them and have no live.com account.
- vetinari 10y agoHow did you get around not having live.com for MS Office? I've got the retail box of 2016 for Mac (not the 365 one) and it still required me to make one :( At every launch, it connects to login.live.com and live.com.akadns.net.
- konceptz 10y agoI do. I often don't like ms products sending crash information but need those updates. It's manual but something I prefer.
- koolba 10y agoHow does this work? Does it override the networking DLLs to proxy the socket creation calls?
- deleted 10y ago[deleted]
- coldtea 10y agoLike any other firewall... It's a kext (OS X kernel plugin)
- nosuchthing 10y agoApplication layer API though OSX.
- zitterbewegung 10y agoThis is a prime example on how to make a landing page for a product. I understand what you are selling and why I would want it. The product looks great and I think I'll try it out after work.
- Periodic 10y agoThe only change I would make is to add an additional call-to-action button at the bottom. I got to the bottom and didn't know what to do next and had to scroll back to the top to find the trial/buy buttons.
- skyo 10y agoIt's pretty good, but I feel like the screenshots don't really convey the app's value very well. Maps wants to connect to maps.apple.com? Of course it should. Itunes wants to itunes.apple.com? Well, yeah. I'd much rather see a screenshot of some app trying to connect to a sketchy or surprising domain. I think that would really drive home the app's purpose and make it look less like nuisance that's going to bug me every time I launch Apple Maps.
- josho 10y agoAnd that's why I fail to see the value for this. Does anyone use this for reasons other than blocking license validation checks on pirated software? Because that's the only reason I can think of for getting this.
- justusthane 10y agoI'm going to try it right now for controlling what's using data when I'm tethering via my phone.
- cuckcuckspruce 10y agoYes. I use this to control what information my Mac sends back to Apple. My workflow for the first system on a network is to install the OS offline, then install Little Snitch from a thumb drive from a trusted system. I set it to Silent, Deny All mode and turn off all rules except for the rules that allow software to make (not receive) connections to the local network. Then, and only then, I connect the network cable and try to pull an IP address. If you're using dhcp then this will fail. To deal with that, I create a profile that applies only when connected to my home network and then add an allow rule to let dhcpd/discoveryd (IIRC) to pull IP addresses. I then try to open up Safari and browse to, say, Google. This will typically fail for two reasons: outgoing DNS queries are not allowed outside of the network and Safari doesn't have rights to connect outside the local network. If my DNS servers are outside of my local network I add a rule to allow the DNS lookup process to connect to only the DNS servers I have defined. I then give Safari allow rules for ports 80 and 443. Both of these rules are added to the home network only profile. From there, I'll try to access the App Store and sort out what rules are needed for that, adding them and then adding them to my home network only profile. At this point, I'll take a firewall rules backup. Now, if I need to reinstall, I can load this rules backup and be able to browse the Internet, pull system updates, and then evaluate other software that needs network requests. Software that tries to connect is logged, and each connection is logged. For software that is too "chatty", trying to talk to the network when it shouldn't, I'll add deny rules so they don't spam the failed connections log. Other software will have case-by-case exceptions made for it as necessary. Generally, all of my allow rules will stay in my home network only profile, but there are a few that I'll always allow out. These are often SSH connections as they should be secure no matter where I'm at.
- alphonsegaston 10y agoLittle Snitch is at once both great and horrifying. If you watch the day to day stuff that happens on MacOS, you'll see that Apple's reputation for security and user privacy is a pretty low bar. Aside from the constantly pinging Apple defaults, so many third party apps are just all the time phoning home to corporate servers when they're not even in use. Chrome can really just look for updates when I open it, not check in with Google about god knows what every thirty minutes.
- libeclipse 10y agoSomething like this would be brilliant on Android. Anyone know anything related? It'd be great if it was for non-root too, but I'm not sure if it's possible.
- deleted 10y ago[deleted]
- therealmarv 10y agoI think this is not possible by design (every app can go online). Adguard (which is an adblocker, runs without root) is installing a local VPN where you can add rules but I think (but not sure) you cannot distinguish between which program makes this request. So with this local VPN approach you can block certain domains/IPs with rules system wide.
- therealmarv 10y agooh maybe you have luck. Just found this: mobiwol http://android.stackexchange.com/a/40926/57180 http://android.stackexchange.com/a/40926/57180
- Couto 10y agoI think AFWAll[1] is what you're looking for, at least the closest I know. [1] https://github.com/ukanth/afwall https://github.com/ukanth/afwall
- ChrisGranger 10y agoI've been using NoRoot Firewall [1] for blocking access to the internet on a per-app basis and haven't had any issues with it. [1] https://play.google.com/store/apps/details?id=app.greyshirts.firewall https://play.google.com/store/apps/details?id=app.greyshirts...
- bostand 10y agoThat looks really good, thanks! I assume it works as a proxy?
- vijucat 10y agoPlease steal this idea and make a product; I'll be your first paying customer: Data Loss Protection (DLP) for retail consumers. DLP (see http://whatis.techtarget.com/definition/data-loss-prevention-DLP http://whatis.techtarget.com/definition/data-loss-prevention... for a definition) goes beyond what Little Snitch does and does packet inspection to ensure that credit card numbers (for example) are never sent out from your network / box. Ideally, you can add regular expressions to define other PII that shouldn't be allowed to be sent out (your name, address, etc;). DLP products exist for corporate use, but I don't know of any lightweight + inexpensive one for personal use. WireShark, Fiddler or Charles can incorporate this functionality, if I am not wrong. Not sure how one would MITM SSL with WireShark, though.
- therealmarv 10y agoThat is an interesting approach. But the simplest encryption (e.g. a simple XOR) will go around this problem very easily.
- vijucat 10y agoI see what you're saying. So DLP is useful only for naive attempts.
- EdHominem 10y agoYes, I worked on a product with a DLP feature we touted yet it would fail to identify credit cards if you put extra characters between sets of numbers. It sounds good, and because compliance is about by making good-sounding things mandatory (weekly password rotation, yay! /s) it got mandated in a lot of places. And it did catch mistakes, like accountants sending the wrong files or to external addresses. Which I guess is justification for it right there. But it's billed as a stronger (ie hacker) protection, for which it's useless, so I never liked it. I think the world would be safer with an email plugin that helped you by suggesting that you should not send a document to a given address, based on rules and observations. It'd only be a suggestion so nobody would expect miracles, but it'd stop all the unintentional mistakes our system stopped, for a fraction of the price.
- jedisct1 10y agoLittle Snitch is a fantastic way for people to shoot themselves in the foot. Most people using it have no clue what they are doing, block random things, and prevent software from working as expected. Not only this can make things less secure by breaking features such as automatic updates, it also makes developer's life miserable by having to provide support to people running their software in a half broken environment.
- nix0n 10y agoI don't buy this argument. The canonical usecase is to block a program from accessing the internet at all. It blocks updates, sure, but you still end up more secure if there's no network in or out at all. Local applications should be able to deal with running offline.
- brians 10y agoBad network connectivity blocks random things too; it seems reasonable to expect any supported application to cope. I absolutely use Little Snitch to block automatic updates of some apps that try to download updates over port 80---I don't trust them to have gotten the authentication right. I'd rather manage those through Homebrew & Caskroom.
- jedisct1 10y agoBad network connectivity: 1) is not permanent 2) does not block connections to localhost
- Sykox 10y agoOh Really! what about those malicious developers who want to snoop in and steal our data or bloatware or ad serving compaines who just want to intrude in our system. or what about adobe who runs a fucking system level service to update a simple reader which i want to control when and how to update. One should be in absolute control how the network and data is consumed that to clearly and transparantly
- khana 10y ago
- icanhackit 10y agoLong time LS user and love it - yes the constant notifications will tax your Qi but once you've set up the bulk of your rules it'll give you a lot of peace of mind. Also grab Lingon X if you're serious about control.
- therealmarv 10y agoSerious question: Can I use only profiles (e.g. no connection until VPN is connected) and the rest of the time Little Snitch should behave like it's not installed? I'm not a big fan of watching every connection... have done this in the distant past with Zone Alarm and Windows and it was more bothering than anything else. I also doubt it increases my personal security a lot.... especially when I think about my normal Android phone which is sitting beside my PC.
- herghost 10y agoYes, I used to use it and had it set up like this. You create one profile which basically allows only the VPN negotiation daemon to access the network, and then another profile where there is no alerting or blocking. Your Mac will be very unhappy when on the first profile though - seemingly everything will constantly attempt to call out because it can see an active connection. I ended up removing Little Snitch because I felt that it was causing instability. I could never pinpoint the issue, but things seemed much more flaky when it was running. YMMV, and I was using it a major release ago so things might be better now.
- therealmarv 10y agoThanks for your in detail answer! Makes me think I should probably not invest in Little Snitch.
- andrenotgiant 10y agoI wish something like this could run at the router level. I am certain my low-end IoT devices are sending out data I don't know about.
- ComodoHacker 10y agoYou want to see a warning every time a host in your home network tries to connect to the Internet?
- tedmiston 10y agoYou only have to see the connection to a server once if you mark it approved forever.
- bisby 10y agoA proper config could easily fix that. Either whitelist certain devices for unrestricted access. Or blacklist devices to have to obey the config parameters. And then parameters for which ports and destinations things should be allowed access to on a per device level... Which is literally describing a firewall/iptables once you drop the "established" incoming rule and block outgoing. Basically, "I want a router iptables configurator with notifications"
- bsmartt 10y agowhy was this posted today? I bought Little Snitch 3 in January 2013. I was thinking maybe this was a new major version but it's not.
- whorleater 10y agoSomeone probably stumbled upon it and found it useful? Little Snitch has been an OS X staple for a while now, especially for those who were involved in the pirated apps scene.
- mkj 10y agoObjective Development (the developers) are a nice company, also providing V-USB - a bitbanging USB implementation for AVR microcontrollers without USB support. https://www.obdev.at/products/vusb/index.html https://www.obdev.at/products/vusb/index.html
- lazyjones 10y agoI tried an earlier version of this and was a bit disappointed by the (apparent?) lack of information regarding these connections from applications, since there's so much going on on OS X and it's hard to tell what's legitimate and what isn't. It would be great if we could record traffic on a per-application/process basis and display it comfortably, or even have some built-in heuristics to identify common tasks like "Firefox update check" or "iCloud authentication". It's very similar to the venerable "Spybot S&D" on Windows (the "TeaTimer" functionality, now apparently called "Live Protection": https://www.safer-networking.org https://www.safer-networking.org).
- frankquist 10y agoI have the same thing with system monitors. So many processes for which I have no idea if they're legit.
- whorleater 10y agoLittle Snitch 3 has the research assistant thing where you can check each application and process to verify if it's legit against a database.
- steinex 10y agoBesides the other replys that suggested Research Assistant: Little Snitch is actually able to write pcaps per application so you can then analyze with Wireshark. Killer feature, imo.
- bredren 10y agoUsually a google search resolves these questions. However, it is a big problem for when I have a non-technical person using a machine with this tool installed. I have heard, "I never know what to do when I see these popups." Unfortunately, I don't think the research assistant will help them either.
- fnl 10y agoThat depends on your POV. Is iTunes phoning home legitimate traffic? Maybe for some/most, but I certainly block those attempts, to me iTunes is just a nuisance app, like GarageBand and a few others. LS does an excellent job at selecting the vital connections as valid and then let you decide if you want to tell Apple & Microsoft & Friends more or if you actually preferred the OS would not.
- mostafah 10y agoI’ve been using this happily for a long time. For those taken back by the endless prompts on the first run: that’s only for the start. Select “forever” for connections you trust and you’ll soon have much less prompts. On a side note: the developers also have Micro Snitch, an app that warns when the camera or the microphone on your mac is in use.
- AndersSandvik 10y ago| Select “forever” for connections you trust But how do you know what to trust?
- flanbiscuit 10y ago> On a side note: the developers also have Micro Snitch, an app that warns when the camera or the microphone on your mac is in use. I did not know that, that's awesome. I'm going to check that out. link for anyone that's interested: https://www.obdev.at/products/microsnitch/index.html https://www.obdev.at/products/microsnitch/index.html
- Sykox 10y agoIs there one absolutely similar to windows? Closest i found was GlassWire
- Semaphor 10y agohttp://www.binisoft.org/wfc.php http://www.binisoft.org/wfc.php It works with the windows firewall. Only the registered version allows notifications for blocked outbound connections ($10 "Donation" required)
- chrisper 10y agoYou could just buy the whole security suite of your firewall program which comes with a firewall probably. For example ESET Cybersecurity comes with a firewall.
- j45 10y agoI used to use something called Tiny Firewall, was quite capable and similar. Not sure what happened to it. http://www.oldversion.com/windows/tiny-personal-firewall/ http://www.oldversion.com/windows/tiny-personal-firewall/
- jstoja 10y ago> A firewall protects your computer against unwanted guests from the Internet. > But who protects your private data from being sent out? A firewall? No kidding, a firewall is not supposed to only block incoming traffic...
- tedmiston 10y agoThe built-in OS X firewall blocks incoming connections only. https://support.apple.com/en-us/HT201642 https://support.apple.com/en-us/HT201642
- rbritton 10y agoNot related in any way, Little Flocker[0] is a similar program but for file access. It's a little rough around the edges but has been improving steadily. [0]: https://www.littleflocker.com https://www.littleflocker.com
- zomg 10y agoi used littleflocker for a few months and, while it worked really well, it slowed my machine down sooo much. perhaps the newer releases perform better.
- theli0nheart 10y agoThe newer releases are much, much faster. You should give it another shot.
- beagle3 10y agoCan it be used to stop OS X Spotlight from putting DS_store in every directory it sees? Edit based on gumby's response below: can it stop finder from littering in every directory it sees?
- gumby 10y agoSpotlight isn't putting that file there; that's where the Finder stores the directory-specific preferences (window size/position, list vs icon display etc). If you don't use the Finder (which I mostly don't) then you'll never see these files. Spotlight maintains its own database in /
- swaits 10y agoI have this at the bottom of my .zshrc just for this reason: # remove any .DS_Store files # (run in a subshell to suppress background job number info being printed) ( ag --hidden -u -l -g '\.DS_Store$' |xargs -n 1 rm -f & ) > /dev/null 2>&1
- tedmiston 10y ago> Research Assistant > Have you ever wondered why a process you’ve never heard of before suddenly wants to connect to some server on the Internet? The Research Assistant helps you to find the answer. It only takes one click on the research button to anonymously request additional information for the current connection from the Research Assistant Database. I'm so glad they built this feature. The hardest part about using Little Snitch is trying to figure out whether processes that look like system or daemons are making legitimate connections.
- deleted 10y ago[deleted]
- Fnoord 10y agoEh, it is not at all a new feature. Lavasoft AdAware did this in the 90s, running on Windows 9x. Apparently Murus Firewall does it as well.
- yduuz 10y agoTry NetBalancer, along with connection/traffic it shows also process info, its parent process and so on: https://netbalancer.com https://netbalancer.com
- elastic_church 10y agobut if I block Little Snitch from Little Snitch, will Research Assistant still work?
- admax88q 10y agoProtect your privacy by running this proprietary application!
- DavideNL 10y ago...which is deeply installed into your system and has (had) plenty bugs for others to exploit. i guess it can protect your privacy but also makes your system less secure to advanced attacks. Same thing can be said of AV-scanners.
- uxp 10y agoThis proprietary application has been under development for almost a decade. While it has had it's share of vulnerabilities as would any application it's age, they've also had that long to develop a reputation in the MacOS ecosystem. I'm no expert on LittleSnitch or Objective Development, the company behind it, but I can't remember any time they've been caught doing shady or unethical things in the time I've been using it (since about 1.x days). The last disclosed vulnerability that comes to mind (CVE-2016-8661), while being a nasty privilege escalation, was responsibly disclosed and quickly dealt with.
- lrem 10y agoOn a proprietary hardware, with a proprietary firmware and communicating over a network you don't control end-to-end! Better don't start thinking about the other end... ;)
- admax88q 10y agoYou're right! The situation isn't perfect so we should just give up!
- deleted 10y ago[deleted]
- Hernanpm 10y agoI noticed no one mentioned https://www.tripmode.ch/ https://www.tripmode.ch/ I used to use Little Snitch before but it was to complex for what I wanted to do, allow disallow internet access to certain apps, tripmode does the trick in the simplest way I've even seen.
- salzig 10y ago»TripMode activates itself on networks where you used it before.« Wow, that's amazing. Apple should buy them and make this feature default :-)
- DavideNL 10y agoLittle Snitch can do this also, called "Automatic Profile Switching".
- chmars 10y agoTripMode doesn't catch all traffic, for example traffic from Arq backups.
- kilroy123 10y agoTrip mode is nice, but it's pretty darn buggy, and hangs a lot. I also never see any updates to it. Which is frustrating as a paid user.
- rwinn 10y agoFirst thing I install on any new system, couldn't recommend it more! And the ability to do per-application captures and open them in wireshark is excellent for debugging.
- djsumdog 10y agoThere's a great Defcon talk about someone breaking Little Snitch: https://www.youtube.com/watch?v=sRcHt-sxcPI https://www.youtube.com/watch?v=sRcHt-sxcPI
- jedisct1 10y agoThere's an easy way to break it. Connect to random ports/IPs, so that the machine becomes unusable due to the amount of Little Snitch popups showing up. Until the user gives up and disables it.
- DavideNL 10y ago"Silent Mode – Decide Later There are times where you don’t want to get interrupted by any network related notifications. With Silent Mode you can quickly choose to silence all connection warnings for a while. You can then later review the Silent Mode Log to define permanent rules for connection attempts that occurred during that time."
- teaearlgraycold 10y agoThis seems like a joke given that it's not open source.
- eps 10y agoCare to elborate on such bold statement?
- LeoNatan25 10y agoZealotry.
- teaearlgraycold 10y agoThis software seems to exist for people who (correctly) don't trust their own computer's software, and want to keep tabs on it. By distributing Little Snitch as closed source you now need to place your trust in Little Snitch itself.
- srigi 10y agoVote with your wallet.
- twsted 10y agoI think these features should be included in every OS nowadays, like we have firewalls. Anyway, I will probably buy this app, even if I share some concern others have about its own network calls.
- benologist 10y agoOne day consumer rights protection agencies are going to scrutinize what we are doing in the background just like they're starting to do to ads.
- bisby 10y ago4-5 years ago when I last used a mac for work, there was a program that had an unlimited evaluation period and was just setup to nag on launch (like winzip). using little snitch just blocked the nag (literally the license did was remove the nag, so it didnt affect functionality). In the end, I wound up not using the program anyway - I really was just trying to evaluate it without the nag. For some reason sublime text comes to mind? I think I wound up just going back to vim Installing little snitch, I got overwhelmed by how much stuff was trying to make calls in and out. It really does serve its purpose, but you also have to have an idea of what you should be letting out, you can easily break things and if you just "allow all" it somewhat ruins the point of having it.
- problems 10y agoDoes Little Snitch catch process injections (ie: I am currently running in EvilMalware, I open up Chrome, create a new page, write my code into it and create a new thread in it), or is it vulnerable to the same problems of Windows firewall applications before LeakTest and the like. The good Windows firewalls now are able to catch this kind of thing.
- post_break 10y agoI think I understand what you're saying (not very technical) but I have used LS for years. I know that I have blocked microsoft word from specific network abilities and tried to open word files that phone home and LS catches those.
- FullMtlAlcoholc 10y agoIf anyone is looking for a summer application that won't inundate you with so much information, try radio silence
- Girlang 10y agoWhy doesn't it run on Windows? (Though the Windows firewall does a lot of this, it's not formatted as nicely.)
- thehashrocket 10y agoLittle Snitch reminds me of Zone Alarm from back in the day.
- Khaine 10y agoLittle Snitch is great. You need to have a strong understanding of networking and the apps that you use, to use it successfully. It is great at opening your eyes to what apps are trying to connect where, and by catching a cap you can investigate what they are sending.
- markneub 10y agoHas anyone figured out how to stop Google's autoupdate process (ksfetch) from tripping LS nonstop? It spawns multiple new temporary processes when checking for updates, and LS requires a path to a specific process file to block it. This has made LS unusable for me since uninstalling all Google products isn't an option for me.