Little Snitch[1] does a very good job of preventing this sort of attack. Even if they give names to the servers that make me think they're something I want to allow, the time I spend clicking the "Allow" button is well outside the margin of error of the latency measurements. I'm in NYC and the tool places me in Frankfort, Germany. +1 for Little Snitch. [1] https://www.obdev.at/products/littlesnitch/index.html
Yes, I use and love Little Snitch too, but don't you have a rule that says Browser = Allow all?
It only took me a few days to work out whitelists/blacklists for the sites I use often, i.e. most citicards.com subdomains get an "allow" but cardoffer.citicards.com gets a "deny". On other sites I come across it's usually trivial to whitelist the domains that provide their functionality, and most adservers and tracking servers I've already blocked.
Given browsers are the main place I get tracked, putting an allow all for my browser seems to defeat the purpose.
That said, it was pretty annoying the first few days.