3 ms·
Can such thing really improve security? I remember the times when Desktop Firewalls like ZoneAlarm got popular, there were dozens of tech talks that showed how
by stiGGG 9y ago
Can such thing really improve security?
I remember the times when Desktop Firewalls like ZoneAlarm got popular, there were dozens of tech talks that showed how baby simple it was to bypass them. I think it was common sense these times that this tools are nothing than SnakeOil. They are useless against real Trojans and only cause a lot of work for the user with all that false positives. In worst case it's blocking applications from self updating which can lead to a less secure system.
Has this changed nowadays? Especially when we are talking about little snitch which has a really good reputation like I noticed the last years.
- jlg23 9y agoNo, they cannot except for the few users who actually understand what it is all about. I probably did more harm than good by advising clueless OSX-users (as in "ordinary users") to use the Little Snitch. Now they browse as careless as before but they are "safe" because they have a "firewall" (in which they always click "allow forever" anyway). If you know what you are doing it is a pretty useful "pf with desktop notifications". But what I personally use it most for: Binary traffic shaping for the lengthy conversation my laptop has with apple.com. One click and I can suddenly use ssh and watch something on youtube again.
- gt2 9y ago"One click and I can suddenly use ssh and watch something on youtube again." What does this mean?
- r3bl 9y agoSince this is a Linux clone: > They are useless against real Trojans Highly doubt anyone will consider it as a way of protecting against trojans. > In worst case it's blocking applications from self updating which can lead to a less secure system. Since this is mostly done on the package management level, it makes sense to use a tool similar to Little Snitch. You're detecting how apps phone home and nothing more. I would take it a step further and disallow some apps to connect to the Internet at all, and allow some apps to contact only certain web pages. Seems like a good way without spending a lot of time playing with firewalls.
- stiGGG 9y ago>You're detecting how apps phone home and nothing more. But only the harmless or respectively naive ones?