Live data from Hacker News

LittleSnitch for Linux

obdev.at

311–320 of 489 posts

Re: LittleSnitch for Linux

#311
post #262

Earlier quoted context omitted.

Many from linux crowd are slightly paranoid and ideological. I'm as a linux user very reluctant to install anything proprietary that has such sensitive info as my network traffic and would rather use opensnitch or any other foss fork. The same time I don't mind to pay for open-source, I donate several thousands USD per year to FOSS projects. But I guess I'm in a minority here and if you make the whole stack open-sour…

> Many from linux crowd are slightly paranoid Slightly? There are quite a few tin foil hat comments on this submission.

You call it paranoia, I call it zero tolerance for enshitification.

It's like the Nazi bar problem. You need to be vigilant to prevent the thing you rely on becoming yet another platform for Microsoft to exfil your personal data to NSA servers.

Re: LittleSnitch for Linux

#312
post #281
post #263

Earlier quoted context omitted.

> Bartender had no target! It was not an attack. The point is that it shows it can happen. You’re a browser extension developer, surely you know how often it happens that developers of popular extensions are approached by shady businesses and sometimes do even sell. > You can dream up a bunch of absurd hypothetical scenarios, but they are not the reality. As someone else has pointed out to you, not hypothetical. http…

> surely you know how often it happens that developers of popular extensions are approached by shady businesses and sometimes do even sell. Yes, developers of free extensions who sell for a pittance. I don't have a popular extension. My extension is relatively expensive and thus unpopular. I don't have enough users to be interesting to shady businesses. My extension is more valuable to me than to anyone else, because…

> My extension is more valuable to me than to anyone else, because I, one person, can make a living from it.

I believe you, and as a fellow indie developer trust you and your intentions and that you’re careful to not be compromised. But if I’m being honest with myself I don’t have concrete proof of any of those. So I trust but also try to limit the blast radius if anything goes wrong. Does that make sense? I think you might agree there.

Your blog helps with that trust and with understanding the human behind it.

> Certainly it is not suggesting acquiring the company for millions of dollars.

Alright, yeah, I see we’re talking a bit past each other in that regard. You’re right that’s how the conversation started (before I joined in) but I don’t care for that angle fully either. I agree there are more plausible ways to achieve the objective.

> Oh noes, the CIA can now write Daring Fireball articles!

Not sure that’d be a downgrade. Maybe they could fix the Markdown perl script, too. Joking aside, I think there would be better targets, like someone on Apple’s Passwords team.

> What chain? I have no third-party dependencies. If someone can compromise Apple's operating systems

I don’t mean it in the sense of software dependencies, but in the sense that some app you use would compromise you. You know macOS’ permissions are mostly security theatre. We know people inside Apple use third-party apps. I can imagine ways of exploiting that, given a bit more knowledge of people from inside (which could be gathered from working there for a while, trawling social media, maybe reading Gruber’s emails, …).

> I do specifically and intentionally avoid using NPM, because of frequent compromises.

Same, no argument from me there.

Re: LittleSnitch for Linux

#313
post #204

Earlier quoted context omitted.

I think there is a lot of talk (and this is good), but very little action. Market share is still incredibly low for LNX. I believe only a small subset of people actually attempt the jump from WIN to LNX (since most just want to play their games and run their programs without hassle) and then quickly realize that its tougher than they anticipated and swiftly return to WIN.

What’s with the weird abbreviations?

He is saving 4 keystrokes out of ~400 by typing LNX instead of Linux.

Re: LittleSnitch for Linux

#314
I used Little Snitch on Mac a few years ago and liked it, though I wasn't a fan of how (necessarily) deep it had to be in the OS to work. It felt like one of those things where, the moment you have any kind of network connectivity issue, it's the first thing you need to disable to troubleshoot because it's the weirdest thing you're doing.

I guess what I'd really like is a middleware box or something that I could put on my home network, but would then still give the same user experience as the normal app. I don't want to have to log into some web interface and manually add firewall rules after I find something not working. I like the pop-ups that tell you exactly when you're trying to do something that is blocked, and allow you to either add a rule or not.

I'm probably straddling some gray area between consumer-focused and enterprise-focused feature sets, but it would be neat.

Re: LittleSnitch for Linux

#315

Recently I was wondering how viable it is to launch a niche, paid tool for Linux. I found that this is a very rare model, most tools are either just free, supported by sponsorship, supported by some paid cloud-based service that accompanies the tool, use an open-core model with paid add-ons. I wonder if the decision of Little Snitch to make the Linux version free forever was also informed by this "no way to make mone…

As the author of Little Snitch for Linux, I can tell you what drives us: we are a small company where people (not investors) make the decisions. It was a personal choice of mine, driven by a gut feeling. I'm curious about the outcome...

Re: LittleSnitch for Linux

#316
post #167

I know it sounds crazy at this point, but with popular YouTubers switching to Linux, gamers overall well-aware of Steam on Linux advantages and switching as well, plus popular software like LittleSnitch getting ported, 2026 can without irony be named as Year of Linux Desktop, right?

2026 is the year of the linux phone. We need to embrace that the year of the linux desktop (2025) was successful.

I wish. I'm tired of not owning my phone. But I don't see a push being done to get a proper Linux phone

Re: LittleSnitch for Linux

#317

>> The macOS version uses deep packet inspection to do this more reliably. That's not an option here. I thought it would be easier to do DPI on Linux than macOS. No???

eBPF is very limited in the code complexity you can achieve. DPI on QUIC, for example, needs a lot of cryptography. That's simply not possible in eBPF. DPI on ordinary TLS still requires that you collect enough network packets to get the name, hold them back until you have a decision and then re-inject them. Holding back packets is not even possible at the layer where we intercept. And even if we find a layer to do this, it adds enough complexity that we no longer pass the verifier.

Re: LittleSnitch for Linux

#318

Earlier quoted context omitted.

Who remembers BlackICE Defender tho? https://archive.org/details/BlackICE_Defender

I was there for SoftICE and BlackICE. Simpler times.

I remember switching from Win95 to NT4.0 just to be able to use SoftICE properly under Windows without all the stability problems, it was an incredible time! SoftICE felt like absolute wizardry at the time.

Re: LittleSnitch for Linux

#320
post #204

Earlier quoted context omitted.

I think there is a lot of talk (and this is good), but very little action. Market share is still incredibly low for LNX. I believe only a small subset of people actually attempt the jump from WIN to LNX (since most just want to play their games and run their programs without hassle) and then quickly realize that its tougher than they anticipated and swiftly return to WIN.

What’s with the weird abbreviations?

[deleted]
Post reply on HN