6 ms·
People are probably going to be confused between this and the "full" version of Little Snitch. My take on it is that Little Snitch Mini is something you can ins
by ary 4y ago
People are probably going to be confused between this and the "full" version of Little Snitch. My take on it is that Little Snitch Mini is something you can install on a non-technical friend or family member's computer whereas power users may want to stick with the existing offering.
I say this as a long time heavy user of Little Snitch. It's very annoying when you first get it installed, but it provides really useful control over what installed software is getting up to. After a time you settle into a natural rule set for your personal patterns and only see alerts when new or updated software tries a network connection that hasn't been seen before.
"Mini" strikes me as much more of a fire-and-forget product, which I appreciate but won't personally use.
- dmix 4y agoI've always thought this should be a feature in an OS for advanced users. Combined with some OS level security optimizations it could be quite a powerful security feature for the paranoid and at-risk. I haven't tried mini but there's probably plenty of UX gains in between the standard Little Snitch fine control approach and the UBlock Origin style community curated defaults where control/customization is optional/on-demand.
- ary 4y agoCompletely agree. Occasionally I run Charles Proxy[1] on my iPhone to analyze network activity and am disturbed by what I see. Software shouldn't be able to open arbitrary network connections without user consent/control, but we're not there yet to a large enough degree on mobile unfortunately. [1] https://www.charlesproxy.com/documentation/ios/ https://www.charlesproxy.com/documentation/ios/
- KyeRussell 4y agoThe reality is that this sort of control would only be attractive to a very very small fraction of users, and no, not just because ‘people don’t care about privacy’ or whatever. There are just very few situations where someone is going to be able to look at this sort of data and do anything meaningful with it, especially when a) most apps are justifiably internet-connected, and b) the homogeneity of public cloud infra means you can’t really tell anything apart from endpoint alone.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- rolfrp 4y agoA good set and forget option for the non-tecnical or those that can't be bothered is https://www.iantispy.com https://www.iantispy.com, basically just does it's thing and doesn't nag to upgrade.
- TedDoesntTalk 4y agoThis product looks a little scary. The ensure mentions no address or names, just that it’s made in Australia and an email address for support. You’re giving this app complete control of your system and have no idea what they’re doing with the data. At least with Little Snitch and uBlock Origin, I know who is behind it and maybe there is safety in numbers of users.
- rolfrp 4y agoYeah nice one... Little Snitch is made in Austria and has email for support. The one I suggested is made in Australia and also has email for support. They are both offered by registered companies with their relevant registration numbers shown on their respective sites. Both have a privacy policy and a terms of service. Both "have complete control of your system" (whatever that even means, neither requires elevated privs). Seems pretty standard. iAntiSpy is also on the App Store, so there's that too.
- eviks 4y agoBut you don't have to do it yourself, that's what all the blocklists more knowledgeable people have created are for!
- Flimm 4y agoPrivacy is not the only use-case. Some users need to monitor data usage to avoid bills they cannot afford.
- kalleboo 4y agoStarting in iOS 15.2 you can turn on the App Privacy Report to log which domains each app on your phone connects to https://support.apple.com/en-us/HT212958 https://support.apple.com/en-us/HT212958 It would be nice for them to add a block option in there as well
- wepple 4y agoWow, just wow. I had no idea this existed, that’s awesome. Thank you!
- jjoonathan 4y agoYes, but these days commercial OSes are seeing a hefty uptick in "first party malware," so to speak, making a third party audit attractive for reasons completely independent from technical integration.
- elesiuta 4y ago> I've always thought this should be a feature in an OS for advanced users. Combined with some OS level security optimizations it could be quite a powerful security feature for the paranoid and at-risk. I agree, by integrating it with an OS with good sandboxing you can provide some powerful security benefits, otherwise the main use cases I see are marginal privacy improvements by blocking telemetry from non-malicious apps, or reducing bandwidth usage. Android does a pretty good job of this with its sandboxing and the network permissions for apps, and you can view the data usage per app in your settings. edit: here is a good resource explaining Android security features and firewalls https://madaidans-insecurities.github.io/android.html https://madaidans-insecurities.github.io/android.html
- lwhi 4y agoIsn't this just a firewall?
- dmix 4y agoYes it's a friendlier desktop interface to a whitelist firewall. Rather than the usual blacklist approach used when engaging with the internet.
- yuuho 4y agoAnything external to the OS level is doomed anyway, from the security standpoint. APIs offered to the good guys can be misused by the bad guys. You see this with all those snakeoil virus scan offerings which dramatically increase attack surface (exploited regularly, but that's not what Symantec an friends are telling you). Plus, anything external to OS level is easier to trick into not seeing what you are doing. And again, if sth external can install itself so deep into the OS that that's hard, then the bad guys can do that too and hide.
- oktwtf 4y ago> Find the Snitch that fits you best! https://obdev.at/products/littlesnitch-mini/compare.html https://obdev.at/products/littlesnitch-mini/compare.html
- chatmasta 4y agoLittle Snitch is great, but it does a bit too much for my liking. I've been using LuLu [0] which is a free product from Patrick Wardle, and I'm pretty happy with it. It mostly stays out of the way and I just need to approve new connections the first time I run an app. [0] https://objective-see.org/products/lulu.html https://objective-see.org/products/lulu.html
- bredren 4y agoDo you use Spaces in MacOS? LS seems to have trouble popping transfer attempt warning modals even if set to all desktops.
- chatmasta 4y agoI think so? If that's what the thing is called when I swipe between desktops. I've only used LuLu on this machine though, and it seems to have no problem (though I guess I wouldn't notice if it wasn't popping up sometimes). One thing I have noticed with LuLu is that the connection attempt sometimes shows the address of my VPN server rather than the actual upstream destination address of the request. But sometimes it shows the upstream - I'm not sure what the pattern is there.
- dhess 4y agoI've seen this recently, but only in the last few months, after years of using Little Snitch with Spaces, so I think it's a new thing either with the most recent version of Little Snitch, or macOS Ventura.
- bredren 4y agoSame experience. Worked perfectly fine before. I wrote w LS support, it is a Ventura-related issue. They've made a request, but it appears Apple has yet to address the problem. This, unfortunately, is a major problem for my use of LS. Interrupted connection attempts happen silently and result in different behavior for each app they affect. I've had the most problems with requests from pycharm, where the binary is updated regularly and needs a bunch of re-authorizations. I'm ready to give up on Spaces, it is so poorly supported by Apple at this point.
- microtonal 4y agoI have been a Little Snitch user for a long time, but I am still very much interested in Mini. When an App Store version of something is provided, I prefer that because of the mandatory sandboxing.
- TedDoesntTalk 4y agoWhat is the sandboxing done by apps from the App Store?
- microtonal 4y agoSee: https://developer.apple.com/documentation/security/app_sandbox/protecting_user_data_with_app_sandbox https://developer.apple.com/documentation/security/app_sandb... The most important property is that the app cannot read/write arbitrary files/directories in your home directory [1]. All access is mediated through privilege-separated open/save dialogs or drag and drop (which creates a link to a file/directory in the app's sandbox). I do trust Objective Development (the makers of Little Snitch), but with any application processing untrusted input, there is always the risk of compromise and its good if the compromise is limited to the sandbox of the app. [1] Though access to certain directories also requires confirmation for non-sandboxed apps in recent macOS versions.