3 ms·
Last time Little Snitch was discussed here on Hacker News[1], I mentioned this: One preset that I would love is "maximum privacy while user initiated outbound
by computator 9y ago
Last time Little Snitch was discussed here on Hacker News[1], I mentioned this:
One preset that I would love is "maximum privacy while user initiated outbound still works". So my browser would work because I initiated it, but everything OSX or apps do in the background are blocked. Automatic updates are blocked? Good! Network time sync is blocked? Fine by me. Only what I initiate gets through. Can you do that as a preset please?
Did they do that?
Seriously, I love the idea of a reverse firewall, but I don't want more work to do. I don't want to analyze connections, look at visualizations, read logs, react to alerts, set up filters, and configure rules.
I just want a high security, maximum privacy system.
[1] https://news.ycombinator.com/item?id=13443858 https://news.ycombinator.com/item?id=13443858
- Philipp__ 9y agoMy problem with Little Snitch is that it throws too much information at me, or it's better to say that I care too much for the information that it provides (and it provides a lot of information). What I would like to see is exactly what you said, a preset that would disable everything besides browser and what I initiate. Edit: Ok so I installed Beta, and it asks you on initial setup page if you want to enable or disable all iCloud and macOS services (respectively, they are completely separated options). That's cool!
- mtgx 9y agoI don't know how Little Snitch does it as I've never used it, but one of my favorite UX/UI implementations for something like this is how GlassWire does it. When something connects to the outside, it subtly notifies you about it, you see everything in an easy to read list, and you can also easily take action like instantly-block something. There is no myriad of popups and alerts and a whole multi-step process to disable something, which is how most such solutions do it. For something that would "disable everything by default" I would simply like to get a GlassWire-like +1 notification on the icon, and then I should be able to see a list of "last blocked" so I can troubleshoot myself later if something went wrong.
- Fnoord 9y agoThat's what Little Snitch does as well. Its nothing new though. Layer-7 firewalls ("personal firewalls") have existed for desktop OSes for a while. I ran them in end of 90s on Windows 9x. Software such as ZoneAlarm, and there were others as well (IIRC LavaSoft had one, but not sure). Nowadays, Windows has one build-in.
- ghshephard 9y agoI don't know if you can do it as a preset in V4, but in V3 I have custom profiles for "Locked Down" Nothing, "Expensive Network" Basically a tiny handful of services - NTP, DNS, and web browsing, "Secure" - Allow things like Photo Syncing, and some other MacOs services, and "Wide Open" - allow pretty much anything that looks reasonably kosher. That's trivial to do with little snitch.
- computator 9y ago> That's trivial to do with little snitch. It's not trivial unless you have a lot of network, sysadmin, and OS X background. You have to think about a lot of issues of what to permit, what to deny. Then you still get alerts and have to research the things that want access. I'm reluctant to deny unfamiliar system apps in case I break something and later have to spend a half a day tracking down mysterious behavior. The developers of Little Snitch have this knowledge. They could create presets for common situations. The only preset I want is "maximum privacy while user initiated outbound still works". I'd be satisfied even with cookbook step-by-step instructions for such a preset.
- skibble 9y ago'The developers of Little Snitch have this knowledge. They could create presets for common situations.' Luckily, that's exactly what they're doing for v4. Hooray!
- ghshephard 9y agoThink about it this way - your computer works fine offline without internet connectivity, so denying access to system utilities isn't going to do any real damage. Using little snitch to "Deny All except Safari Outbound" is exactly the same as working offline, except that your web browser now works. No Networks/Sysadmin/OS X experience required. By and large, the largest and most annoying culprits on my systems are the OS X system utilities doing background updates, syncing photos, etc.... Ironically, they are the ones I most want to shut down when I'm not on home WiFi. Plus, if you have 15-30 minutes one afternoon, it's a great way to get insight into what your system is doing, and gain some (small) amount of comfort that you know what's going in/out of your system. Well, that is, everything that isn't bypassing the kernel in the first place.... :-(
- waisbrot 9y ago> One preset that I would love is "maximum privacy while user initiated outbound still works". So my browser would work because I initiated it, but everything OSX or apps do in the background are blocked. I don't know how you imagine this would work. If I load up a GitHub PR in my browser and then swap to my editor, will the page update when I get a review comment 30 minutes later? If I launch a program and it immediately phones home, is that blocked?
- computator 9y ago> If I launch a program and it immediately phones home, is that blocked? Yes. > I don't know how you imagine this would work. That's why I'd like Little Snitch to figure it out. There will be judgment calls, edge cases, and decisions. If there's anyone capable of doing it, it's the developers of Little Snitch. I don't see a theoretical reason why we can't have "maximum privacy while user initiated outbound still works" -- for some reasonable definition of those words.