Live data from Hacker News

LittleSnitch for Linux

obdev.at

461–470 of 489 posts

Re: LittleSnitch for Linux

#461

Earlier quoted context omitted.

Little Snitch is bound to the API provided by Apple. The NEFilterDataProvider API calls `handleNewFlow()` only after sending out the first IP packet. Version 6 added DNS encryption and in principle we could filter lookups (similar to PiHole) at this level. That brings other issues, though: This filter is system-wide, so process-specific rules (and overrides) would not work. And results can be cached by mDNSResponder.…

>in principle we could filter lookups I've been telling people about ya'll's DNS leaks for over a decade [3] — glad to finally hear back — most people won't believe me [0] until this flaw is demonstrated on their specific machine (easy enough). Those already using LittleSnitch will then typically set up better filtering (e.g. DNS white/blacklist, PiHole, et.alius). And until the behavior is fixed, I will keep spreadi…

The eBPF filter in Linux Snitch decides immediately, so no TCP handshake leaks. But, as a consequence, we cannot inspect packet headers to verify the remote name and it's easier to trick it to show a false name. Little Snitch for Linux is not a security tool.

Re: LittleSnitch for Linux

#462

Earlier quoted context omitted.

From me. OD is a great dev firm. Do you understand my statement?

>OD is a great dev firm Please see my response to OD [I presume /u/littlesnitch is OD representative] . Nobody is disputing their "greatness" — I'm just criticizing a flaw in their approach to domain name filtering. Hopefully OD will refund my original license (unused for many many many years, after I discovered this flaw). That would be good, in principle; good business. Hopefully OD will be more forthcoming in this…

Are you blaming me for promoting software that I didn't write?

Re: LittleSnitch for Linux

#463
post #262

Earlier quoted context omitted.

Many from linux crowd are slightly paranoid and ideological. I'm as a linux user very reluctant to install anything proprietary that has such sensitive info as my network traffic and would rather use opensnitch or any other foss fork. The same time I don't mind to pay for open-source, I donate several thousands USD per year to FOSS projects. But I guess I'm in a minority here and if you make the whole stack open-sour…

> Many from linux crowd are slightly paranoid Slightly? There are quite a few tin foil hat comments on this submission.

> There are quite a few tin foil hat comments on this submission

Everybody says this until they get fucking pwned at work or have their own data or children's data taken and used.

Then it's "not so tin-foily" and maybe it changed your entire life.

You're either paranoid, or a fool at this point.

Re: LittleSnitch for Linux

#464
post #183

Earlier quoted context omitted.

Yes, PiHole is the most common, but malware can easily bypass that using shared domains, P2P or IP addresses directly. Use a filtering proxy instead and no gateway / route to the internet.

1) Dnsmasq, you don't need the whole PiHole for that. 2) You're advising security through obscurity instead of a network namespace + firewall.

Please explain #2. How is a filtering proxy security through obscurity?

Re: LittleSnitch for Linux

#465
post #181

Earlier quoted context omitted.

It's because there's no way to make universal kernel modules/drivers, like it is on Windows.

The way to make kernel modules is to submit them to the kernel. Not really sure what a “universal kernel module” really is. Also that seems irrelevant because it seems this was implemented in eBPF so no kernel modules are required.

> The way to make kernel modules is to submit them to the kernel.

Then it would need to be published as GPL, but with no guarantee that it will ever be accepted.

> Not really sure what a “universal kernel module” really is.

A .ko that can be loaded in a wide range of kernel versions.

> Also that seems irrelevant because it seems this was implemented in eBPF so no kernel modules are required.

And it has serious limitations. There's a chapter of them in the readme.

Re: LittleSnitch for Linux

#466
post #167

I know it sounds crazy at this point, but with popular YouTubers switching to Linux, gamers overall well-aware of Steam on Linux advantages and switching as well, plus popular software like LittleSnitch getting ported, 2026 can without irony be named as Year of Linux Desktop, right?

France is trying to switch to desktop linux. https://news.ycombinator.com/item?id=47716043 and https://news.ycombinator.com/item?id=47719486

I think AI also makes it easier to deal with issues that come up.

Re: LittleSnitch for Linux

#467

Earlier quoted context omitted.

>in principle we could filter lookups I've been telling people about ya'll's DNS leaks for over a decade [3] — glad to finally hear back — most people won't believe me [0] until this flaw is demonstrated on their specific machine (easy enough). Those already using LittleSnitch will then typically set up better filtering (e.g. DNS white/blacklist, PiHole, et.alius). And until the behavior is fixed, I will keep spreadi…

The eBPF filter in Linux Snitch decides immediately, so no TCP handshake leaks. But, as a consequence, we cannot inspect packet headers to verify the remote name and it's easier to trick it to show a false name. Little Snitch for Linux is not a security tool.

>Little Snitch for Linux is not a security tool.

What is it, then?

Re: LittleSnitch for Linux

#468

Earlier quoted context omitted.

>OD is a great dev firm Please see my response to OD [I presume /u/littlesnitch is OD representative] . Nobody is disputing their "greatness" — I'm just criticizing a flaw in their approach to domain name filtering. Hopefully OD will refund my original license (unused for many many many years, after I discovered this flaw). That would be good, in principle; good business. Hopefully OD will be more forthcoming in this…

Are you blaming me for promoting software that I didn't write?

No, I'm pointing out (against your initial claim) that OD's attention to detail might be lacking, here... at least they ought'a disclose the described/known vulnerability.

Instead, /u/LittleSnitch just commented elsewhere "Little Snitch is not a security tool" — interpret accordingly.

Re: LittleSnitch for Linux

#469
post #174

Earlier quoted context omitted.

So... what if the maker can't make it on donations only?

Then development will stop and users don't have the software anymore. If users consider this software important they should donate so they can keep using it.

>and users don't have the software anymore.

Not exactly. Users still have the software. They don't have updates.

See the issue here? Even if someone just fixes some bugs and security fixes - this alone can be time consuming. At the same time many users can just accept the version without those pathes and don't donate.

So you have a choice - continue to maintain the software for less money or to drop it, leaving donating users with no support.

Re: LittleSnitch for Linux

#470
post #206

Earlier quoted context omitted.

Yeah, because no third party program has ever crashed on any other OS. Come on, this is an absurd comment. Linux has its issues, this is not a serious example of what is keeping normal people from using Linux as a desktop OS. Normal people are not installing the first release of a privacy networking tool that requires you to OK connections.

[flagged]

Why are you in a thread about Linux software if you hate it so much? Just felt like spreading some negativity?
Post reply on HN