Live data from Hacker News

LittleSnitch for Linux

obdev.at

151–160 of 489 posts

Re: LittleSnitch for Linux

#151
Wow. I have used Little Snitch on Mac for years, love this!

If anyone from obdev is reading, please give us a way to pay for it, even if it stays free :), I'd love to support development and would happily pay something between the price of Little Snitch and Little Snitch Mini.

Anyway, thanks a lot!

Re: LittleSnitch for Linux

#152

Earlier quoted context omitted.

There was also Tiny Firewall which got bought by Computer Associates around 2005. Probably the most complicated or fine grain control for me at that time in Windows XP.

This is what I used! At some point I managed to block DHCP lease renewals on my computer, and Internet would always stop working after a given timespan. Took a good while to figure out I caused the problem myself.

and that's how you learn...

Shooting yourself in the foot really helps to built intuition!

Re: LittleSnitch for Linux

#153
post #64

Okay hear me out, I use little snitch for a while. Great product. Love finding out what phones where. I make every single request (except my browser, because I'm fine with their sandbox) block until I approve. Recently I was wondering how you really have to trust something like little snitch given its a full kernel extension effectively able to MITM your whole network stack. So I went digging (and asked some agents t…

disclaimer: I co-develop (FOSS) Little Snitch / Open Snitch inspired firewall but for Android

> little snitch given its a full kernel extension

On macOS, don't think Little Snitch needs kernel exclaves / extensions. Apple provides userspace ("Network Extension") APIs (however limited) for apps like Little Snitch to use (instead of pf).

> effectively able to MITM your whole network stack

"MITM" means something else, anywho... if network observability (not firewall) is the primary need, cross-platform (GUI) sniffers like Sniffnet exist: https://github.com/GyulyVGC/sniffnet

Re: LittleSnitch for Linux

#154
post #85

Earlier quoted context omitted.

> Said motivation could be a nation state handing them $XXX million dollars You're missing the most important part of the motivation here: why in the world would a nation-state give a damn about Little Snitch, especially to the tune of $XXX million dollars? A nation-state could pay $XXX million to your significant other to spy on you. But again, a nation-state doesn't give a damn about you.

>why in the world would a nation-state give a damn about Little Snitch, especially to the tune of $XXX million dollars? Per user hacked, it can be very cheap ¹ compared to bribing anyone. And give data/access that SO can't get. State is not interested in you until it does. Being Jewish, Polish, Gypsy, Gay. Or just WrongThinking. Or maybe it becomes super cheap and easy to process all information? 1: it can even be fr…

> it can even be free. You either give us backdoor to all your users or you rot in jail.

It is already a thing, at least in UK and AU [1]:

> Both countries now claim the right to secretly compel tech companies and individual technologists, including network administrators, sysadmins, and open source developers – to re-engineer software and hardware under their control, so that it can be used to spy on their users. Engineers can be penalized for refusing to comply with fines and prison; in Australia, even counseling a technologist to oppose these orders is a crime.

[1] https://www.eff.org/deeplinks/2018/12/new-fight-online-priva...

Re: LittleSnitch for Linux

#156
> For keeping tabs on what your software is up to and blocking legitimate software from phoning home, Little Snitch for Linux works well. For hardening a system against a determined adversary, it's not the right tool.

What would be the right tool to harden in a similar way to little snitch on mac? Meaning intercepting any connection and whitelisting them reliably.

Re: LittleSnitch for Linux

#157
post #69

Earlier quoted context omitted.

That seems... not correct? The comment was asking about preventing a compromised supplier for the developers. A supply chain attack can be anywhere in the supply chain to the target. If I, the end user, am the target, then a supply chain attack compromising the developer of LittleSnitch is effective. I may then be a conduit to compromising other software or components, and would both I and LittleSnitch would be part…

> If I, the end user, am the target You're not a target, anonymous rando.

Many supply chain attacks aim to run malware on the end-users machine to harvest authentication tokens, etc. So pretty much everyone here who is a developer is the target.

Re: LittleSnitch for Linux

#160
post #6

I remember before Little Snitch there was ZoneAlarm for Windows[0] (here is a good screenshot[1]). No clue if the current version of ZoneAlarm does anything like that (have not used it in 2 decades). I always found it weird that Linux never really had anything like it. [0]: https://en.wikipedia.org/wiki/ZoneAlarm [1]: https://d2nwkt1g6n1fev.cloudfront.net/helpmax/wp-content/upl...

> [ZoneAlarm] I always found it weird that Linux never really had anything like it.

There was simply no need for it. GNU provided most of the software, spyware was unknown.

Only since comercial vendors package for linux and bring their spyware along, the desire to inspect network rose.

Post reply on HN