Has this changed nowadays? Especially when we are talking about little snitch which has a really good reputation like I noticed the last years.
Has this changed nowadays? Especially when we are talking about little snitch which has a really good reputation like I noticed the last years.
> They are useless against real Trojans
Highly doubt anyone will consider it as a way of protecting against trojans.
> In worst case it's blocking applications from self updating which can lead to a less secure system.
Since this is mostly done on the package management level, it makes sense to use a tool similar to Little Snitch. You're detecting how apps phone home and nothing more. I would take it a step further and disallow some apps to connect to the Internet at all, and allow some apps to contact only certain web pages. Seems like a good way without spending a lot of time playing with firewalls.
But only the harmless or respectively naive ones?
If you know what you are doing it is a pretty useful "pf with desktop notifications".
But what I personally use it most for: Binary traffic shaping for the lengthy conversation my laptop has with apple.com. One click and I can suddenly use ssh and watch something on youtube again.
What does this mean?