Live data from Hacker News

Little Snitch: Network Monitor and Application Firewall for macOS

obdev.at

41–50 of 118 posts

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#41

I remember installing it on my work machine, and our IT Crowd demanded that I remove it. They didn’t like that it exposed all their sneakware.

Arguably you’re the one installing sneakware on your employer’s machine.

Work machines and personal software/data and vice versa don’t mix well in many jobs.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#42

Little Snitch is one of the best pieces of software out there. It’s essential for every macOS user, works very well, and is a one-time payment. I truly hope it stays that way and doesn’t go down the same path as 1Password. I’m very grateful to the developers for creating such an excellent product. I wish more software were like this.

> and is a one-time payment I feel like I’ve done many one-time payments to get the new version of Little Snitch through the years. I’m not currently using it, but for a long time it was on my list of Mac apps that I feared having to pay to upgrade with every new macOS release.

Paying for an upgrade to a new major version seems entirely reasonable and is the model I strongly prefer vs. ongoing subscriptions.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#43
post #41

I remember installing it on my work machine, and our IT Crowd demanded that I remove it. They didn’t like that it exposed all their sneakware.

Arguably you’re the one installing sneakware on your employer’s machine. Work machines and personal software/data and vice versa don’t mix well in many jobs.

This is true.

I didn’t argue with them, but kept using it on my personal kit.

I think it’s less useful, these days, as Apple is really battening down their I/O hatches. I know that Charles Proxy can miss stuff.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#44

Little Snitch is one of the best pieces of software out there. It’s essential for every macOS user, works very well, and is a one-time payment. I truly hope it stays that way and doesn’t go down the same path as 1Password. I’m very grateful to the developers for creating such an excellent product. I wish more software were like this.

I have it installed on my main Mac. But honestly I don't use it/don't know if it's doing anything. Should I be doing something?

That probably depends on what you do with your computer.

If you regularly clone git repos and run code you didn’t write or run unsigned apps from untrusted developers, it’s probably a good idea to scrutinize the connections that code is making.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#45
post #41

Earlier quoted context omitted.

Arguably you’re the one installing sneakware on your employer’s machine. Work machines and personal software/data and vice versa don’t mix well in many jobs.

This is true. I didn’t argue with them, but kept using it on my personal kit. I think it’s less useful, these days, as Apple is really battening down their I/O hatches. I know that Charles Proxy can miss stuff.

> I know that Charles Proxy can miss stuff.

It would miss anything not using macOS high-level HTTP or socket APIs, right?

If you're concerned about apps surreptitiously phoning home, I wouldn't count on them using those, or otherwise respecting the system proxy settings.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#46
post #23

Earlier quoted context omitted.

Never heard of "nuke and pave" before, nice idiom! https://en.wiktionary.org/wiki/nuke_and_pave

It's by far the most common phrase I've heard used to wipe+reinstall a system in the past 20 years? 25 years? Not just the most popular colloquialism, the most popular phrase, period. My experience is US/West Coast/Tech companies, for reference.

I’ve spent 20+ years in tech in roles ranging from IT to engineering at west coast and midwest companies and this thread is the first time I’ve heard “nuke and pave”.

At the places I’ve been, systems got “wiped” or “re-imaged” most commonly. I suspect this terminology is hyper local.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#47
post #25

For those looking for a good, free firewall for macOS, consider LuLu. https://objective-see.org/products/lulu.html

Other (paid) alternatives: Vallum, Radio Silence - https://vallumfirewall.com - https://radiosilenceapp.com

I feel like macOS has been going the direction of iOS, increasingly locking things down and pushing to a walled garden world. What’s the chance that the next major update or two make changes that prevent utilities from having the access they need to provide these power user capabilities?

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#49
post #21

Firewalls and endpoint security are important, and Little Snitch is pretty good, but this feels like an ad being posted. It’s just a link to the main page of their website: nothing specific to warrant discussion.

It’s an HN “read the room” submission. It’s contextually related to earlier discussion about Apple Photos phoning home without a direct reference to it.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#50
post #46
post #23

Earlier quoted context omitted.

It's by far the most common phrase I've heard used to wipe+reinstall a system in the past 20 years? 25 years? Not just the most popular colloquialism, the most popular phrase, period. My experience is US/West Coast/Tech companies, for reference.

I’ve spent 20+ years in tech in roles ranging from IT to engineering at west coast and midwest companies and this thread is the first time I’ve heard “nuke and pave”. At the places I’ve been, systems got “wiped” or “re-imaged” most commonly. I suspect this terminology is hyper local.

In IT (BBS's) since 1993 or so. Owned a computer store and an ISP. New Mexico. First time I've heard it as well.
Post reply on HN