Live data from Hacker News

Little Snitch Mini

obdev.at

241–250 of 276 posts

Re: Little Snitch Mini

#241

Earlier quoted context omitted.

The problem is: you can't do upgrade pricing in the app store. So your users would have to pay full price for a 2.0 upgrade. You could of course buy outside the app store - but you don't want that. And I don't want that, too (as a dev selling my software). Purchase orders are a PITA and I have been shafted by enterprise more than once. They get their licenses, I'm not getting my money because they just don't pay. Suc…

> The problem is: you can't do upgrade pricing in the app store. That is not a real problem. Many apps handle this by checking for a prior version and giving a discount (see Omni or Affinity approach), by having an upgrade window (e.g. 1Password approach before switching to subs outside app store), or by just charging full freight again (which nobody who values software actually minds, and enterprises that budget ful…

>That is not a real problem.

It is to me. I don't want the app store full with different versions of my software that will confuse any prospect buyer.

I also don't want my main customers to feel shafted because every N months I just push out a new app at full price. What happens to the people who bought like 2 weeks ago? I have only 100 promo codes I can send out - and those who use promo codes can't write a review.

Ah yes, reviews. My $50 Mac App has over 700 reviews (4.8 avg rating). It took years to build that up. I'm not throwing this away just because some corporate admin waves the idea of someone purchasing "15,000" units (which is never going to happen anyway). Heck if you really intended to give me $750k you could contact me and I'd put up a special version of the app just for you. But guess what: You're never going to buy 15k units from me. Neither is anyone else.

So, my main customers are single users who are not in a corporate setting. They are my main source of revenue. I'm not going to fuck with them to get into the "maybe corporate is going to give you a million dollars" lottery. I've been doing this software business shit for too long to be that naive.

You're barking up the wrong tree here. Go to Apple and complain why you can't purchase IAPs with your magical Apple IDs.

Re: Little Snitch Mini

#242
post #239

Earlier quoted context omitted.

> The problem is: you can't do upgrade pricing in the app store. That is not a real problem. Many apps handle this by checking for a prior version and giving a discount (see Omni or Affinity approach), by having an upgrade window (e.g. 1Password approach before switching to subs outside app store), or by just charging full freight again (which nobody who values software actually minds, and enterprises that budget ful…

This is one of the things that bothers me about Apples app install process; I reinstall my OS often and when I start installing software via App Store, Apple displays the price and the notification that you will be charged never giving the user prior indication of whether the app is a new version that you will or will not pay for. With all the brilliant heads behind Apple you would think they would be able to get the…

There's always the "purchased apps" list you get to by clicking on your Apple ID avatar in the lower left corner of the Mac App Store.

Re: Little Snitch Mini

#243

I bought Little Snitch long ago but managed to squander my license a couple of years later. Mini is unfortunately a subscription app, which is something I these days consider a hostile/unfriendly business pattern. I won't be going back. LuLu is a free alternative.

I generally agree with you so I looked it up. In-App Purchases: Yearly Subscription $13.49 Monthly Subscription $1.49 That's surprisingly modest. 3-4 years of subscription approximately being equal to a license sounds reasonable. The real question is, is little snitch rent seeking? Given what happened after Catalina, I am giving them the benefit of the doubt at the moment. Paying for updates before receiving them def…

It is so interesting to see this line of thinking. I am sure it comes with purchasing power or local spend vs saving culture. I mean I genuinely find it interesting. Because subscriptions pile up. They do.

I saw this phenomenon, with horror, devour/take-over note-taking and journal app scenes in almost entirety (except some open source react native/hybrid apps).

Re: Little Snitch Mini

#244
post #61
post #45

Earlier quoted context omitted.

This is why I pay for LS. The whole point of the software is to avoid nonconsensual phone-home; if it does it itself, how or why would you ever trust the developer? I'd literally rather pay for proprietary software than maintain a fork of LuLu.

It's not nonconsensual, you can literally block it with itself.

[deleted]

Re: Little Snitch Mini

#245

Earlier quoted context omitted.

Little Snitch is great, but it does a bit too much for my liking. I've been using LuLu [0] which is a free product from Patrick Wardle, and I'm pretty happy with it. It mostly stays out of the way and I just need to approve new connections the first time I run an app. [0] https://objective-see.org/products/lulu.html

Do you use Spaces in MacOS? LS seems to have trouble popping transfer attempt warning modals even if set to all desktops.

Yup. They have an FAQ on the subject, and claim it's a Ventura bug and not one of theirs.

I've filed a bug report with Apple, for all the good that will do.

What's weird, annoying, and frustrating is that it will work correctly for the first day or two after a reboot, then start exhibiting the bad behavior. Once the "wrong desktop" popups start, they continue until the next reboot.

Re: Little Snitch Mini

#246
post #121
post #70

Earlier quoted context omitted.

Why wouldn't he care? Keeping track of all the subscriptions "forced" upon you is a huge pain in the ass these days – and seemingly getting worse. Personally, I refuse to use subscription services out of principle. I much prefer to pay once and have it off my mind.

Wouldn't a saner way to live be to judge the value you get out of something to determine how much you're willing to pay for its use? Just seems needlessly limiting to act like this out of principle.

As far as I am concerned, subscriptions are an unreasonable hassle. You need to keep track of what subscriptions are active and where you can manage them. And when subscriptions are running, a “did I remember cancelling all the stuff I’m currently not using” is always in the back of my mind somewhere. That’s just annoying noise that I can easily avoid by not using subscription services.

Re: Little Snitch Mini

#247
post #204

Earlier quoted context omitted.

What is your threat model, and what type of traffic are you hoping to block? I never claimed picosnitch to be a firewall. My use case involved running it on servers with a minimal OS where all applications are containerized. My goal was purely monitoring to see if any containers had rogue executables, and go from there. Without the containers, it would be trivial for a malicious program to stop or modify picosnitch,…

I never claimed you claimed it. I was just pointing out the huge deficiency that makes picosnitch not an alternative to the broader use case littlesnitch supports To sidestep the more complicated discussion re. how poor the security architecture of Linux is, let's limit that use case to blocking legitimate apps' connections for privacy reasons

I apologize, that's a fair question given that I named it after Little Snitch. One reason I used the prefix pico is because it's extremely little, supporting only a subset of Little Snitch's features.

On Linux there's already a number of great apps for blocking legitimate apps' connections, however they all still support only a subset of Little Snitch's features, and there wasn't one that offered the subset I provided with picosnitch. Which of those features you consider most important is subjective and dependent on your use case. I consider picosnitch a valid alternative and the core feature to be snitching on programs, the same goes for the new free tier of Little Snitch Mini.

Also like I said above, it is difficult to hash executables and block them without introducing delays the first time anything connects to the internet. If you're only concerned about blocking legitimate apps' connections you don't need them to be hashed since you can trust them not to do anything too nefarious. Personally this was more useful to me, since if I see an unexpected new program or hash during updates, or a new hash outside of updating my containers, I can intervene or have another script stop my containers and alert me. I also get some value from this on my desktop since I do all my development inside containers, and use another drive with Windows solely for gaming.

Re: Little Snitch Mini

#248

Earlier quoted context omitted.

I don't like subscriptions either, but what is the sustainable alternative income source for app developers?

Honest question, and I'm asking because I want to know your take, not because I'm trying to be a dick: why should an app developer have a sustainable income stream from a single app no matter what? Isn't it possible that an app is simple enough that doesn't justify getting a full salary out of it? Again, I'm not trying to be a dick here, I'm just trying to figure out what is the reasoning behind the subscription mode…

I completely agree, many apps don’t justify being a subscription. It depends on the complexity, the frequency of expected updates and new features. Also if there is a cloud storage or paid API component to the app, then a subscription model is practically essential to keep an app running due to the developer’s own recurring costs.

I think like many things it’s not one size fits all.

In this particular case, I think that keeping a firewall utility up to date with changes to macOS and emerging threats would require a modest sustainable income source to make it worthwhile for the developer.

Re: Little Snitch Mini

#250
post #138

Earlier quoted context omitted.

https://www.obdev.at/products/littlesnitch/order.html

This doesn’t contain the mini product

The parent didn't want the mini product. He wanted the full paid version (what you get if you do the IAP in the mini product).
Post reply on HN