Live data from Hacker News

Little Snitch: Network Monitor and Application Firewall for macOS

obdev.at

71–80 of 118 posts

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#72
post #64

Little Snitch is one of the best pieces of software out there. It’s essential for every macOS user, works very well, and is a one-time payment. I truly hope it stays that way and doesn’t go down the same path as 1Password. I’m very grateful to the developers for creating such an excellent product. I wish more software were like this.

I own many more devices than just a Mac. I have an iPhone, Apple TV, Linux box, Windows PC, Nintendo Switch, Quest 2, Kindle. I'd prefer one piece of software that covers all of them over different software for each of them.

This is an application level firewall software. Applications are OS specific.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#73
post #49
post #21

Firewalls and endpoint security are important, and Little Snitch is pretty good, but this feels like an ad being posted. It’s just a link to the main page of their website: nothing specific to warrant discussion.

It’s an HN “read the room” submission. It’s contextually related to earlier discussion about Apple Photos phoning home without a direct reference to it.

My understanding is that there were some issues with Apple often not allowing its own traffic to be filtered via firewalls on its systems.

See discussion:

https://news.ycombinator.com/item?id=25109724

https://news.ycombinator.com/item?id=37500237

If you want to monitor your own network I’ve heard good things about the pi-hole project

https://pi-hole.net/blog/2017/02/22/what-really-happens-on-y...

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#74

Little Snitch is one of the best pieces of software out there. It’s essential for every macOS user, works very well, and is a one-time payment. I truly hope it stays that way and doesn’t go down the same path as 1Password. I’m very grateful to the developers for creating such an excellent product. I wish more software were like this.

This is the absolute top of my wish list for software on iOS (impossible with Apple’s draconian restrictions though).

I'd expect that you could do something like this with the api that vpn software uses

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#75
post #59

For those looking for a good, free firewall for macOS, consider LuLu. https://objective-see.org/products/lulu.html

Doesn't macOS also have a built in (but disabled by default) Firewall? Why does nobody use that?

There are actually two default firewalls. The firewall that's configurable in UI can only block inbound connections but not outbound connections. The other firewall (pf) doesn't have the concept of application so one cannot allow one app to access a remote IP but block another, and I also don't think it supports DNS.

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#79
post #25

For those looking for a good, free firewall for macOS, consider LuLu. https://objective-see.org/products/lulu.html

Other (paid) alternatives: Vallum, Radio Silence - https://vallumfirewall.com - https://radiosilenceapp.com

How would you compare these to little snitch?

Re: Little Snitch: Network Monitor and Application Firewall for macOS

#80

Little Snitch is one of the best pieces of software out there. It’s essential for every macOS user, works very well, and is a one-time payment. I truly hope it stays that way and doesn’t go down the same path as 1Password. I’m very grateful to the developers for creating such an excellent product. I wish more software were like this.

> It’s essential for every macOS user Is it? I'm interested in hearing why. I've been using macOS for ~15 years, so very familiar with Little Snitch. I think I owned a version many years ago but haven't for a long time. I don't really see what I'd use it for. I don't run dodgy software, I don't want to partially break the software I do run by nit picking what connections it can make as that wouldn't improve my experi…

I caught a python ml library phoning home to a chinese server on a project that my company was building. My developer had no idea it was happening but I caught it first run thanks to lil snitch. If deployed this would've been a security escape that would need to be disclosed at a govt level.

Also, Apple. Their junk phones home just about everything you do. 50+ services constantly pinging Cupertino.

Post reply on HN