Little Snitch feature nobody knows about
lapcatsoftware.com
lapcatsoftware.com
Does anyone know if the same thing can be achieved with LuLu? https://objective-see.org/products/lulu.html It looks like it can but I haven't used it yet.
LuLu has a fatal flaw: it drops or closes TCP connections randomly resulting in dropped SSH sessions. No amount of TCP keepalives on the client- or server-side will resolve this. This makes it a non-starter for anyone doing anything real.
Also good:
- BlockBlock - disk access application "firewalling" on top of macOS'es privacy & security settings is very good
- RansomWhere? - ransomware process mass file change interception
- ReiKey - input interception monitor
- ProcessMonitor, DNSMonitor, FileMonitor, TaskExplorer, KextViewer, NetIQuette, Dylib Hijack Scanner, KnockKnock
- Oversight - webcam and audio hijack monitor (although I use ancient EOL Growl + Hardware Growl just to catch hardware events too)
- No longer useful or usable: Do Not Disturb, LuLu
> OverSight monitors a mac's mic and webcam, alerting the user when the internal mic is activated, or whenever a process accesses the webcam.
Since this is a Google domain I wonder if Apple pins the certificates.
I am currently battling a bug on iOS where blocking mask.icloud.com & mask-h2.icloud.com leads to Mail 'checking for email' for a long time. But I can't inspect what is requested. And supposedly, this is the way to prevent iCloud relay: https://developer.apple.com/icloud/prepare-your-network-for-...
Also, I tried replying with NOERROR and NXDOMAIN. Neither work.
https://transparencyreport.google.com/safe-browsing/overview
It would be nice if you could import a text or config file of standard things to allow/block. A general format that people could post, fork, edit, their own variations. Something akin to stevenblack/hosts providing a base list of hosts to block but the list is categorized as well as could be customized.
Another, probably better example, is something that could be saved in a dotfiles repository. You can share it with others but also if/when you need to setup a new computer, you don't have to start have completely fresh with Little Snitch.
E.g. running the android emulator was enlightening :-S
According to https://gdpr-info.eu/issues/consent/
> Consent must be freely given, specific, informed and unambiguous. In order to obtain freely given consent, it must be given on a voluntary basis. The element “free” implies a real choice by the data subject. Any element of inappropriate pressure or influence which could affect the outcome of that choice renders the consent invalid.
Declining terms of service will affect the outcome so it can't be considered "freely given consent".
Little Snitch is awesome, but i had to stop using it at version 5 because it can no longer be installed into a subfolder of the Applications folder.
Mac apps are supposed to be usable from any location (even outside the /Applications/ folder) and i have used hundreds of apps from /Applications/_Apps/ since the Mac OS X Public Beta in 2000 without issue.
Little Snitch >= 5.0 is the only one having problems here, despite supposedly being a "real native Mac app". what gives?
off-topic rant mode off
also makes copying all installed apps to another mac a 1-second thingie
Looks like for me the only thing is Jetbrains IDEs installed themselves there hmm.
That was 30 years ago! Why should Apple stick to a decades-long rule?
It's as if a Windows developer decided their program should only be runnable from a directory under "Program Files". So weird! Do they provide an explanation on their web site for the change?
As a Little Snitch user, I'm glad to be able to tell both Apple and Google "None of your business."
It's a simple little phrase that used to be very common, but people seem to have forgotten it over the last 30 years.
Everyone who has used homebrew knows this one.
I wasn’t familiar with using ‘via’ in rules in LittleSnitch either. Whenever I do ‘brew update / upgrade’, I do often get a whole bunch of alerts about connections, such as: ‘git’ / ‘curl’ via Terminal wants to connect to GitHub.com / githubusercontent / whatever.
Now, I don’t want to blindly give permission to all future curls/git issued from Terminal since that’s huge in scope. But I’m ok with all direct brew commands hitting certain endpoints. Perhaps this is a solution for me, I’ll check it out, trying to make rules for ‘curl’ via ‘brew’
Little Snitch was first released in 2003. Unfortunately, your comment is a stereotypical example of the worst of Hacker News, both condescending and ignorant.
In any case, it's unclear exactly which version of Safari and/or macOS started the specific behavior noted in the blog post. Moreover, as the blog post also notes, it's problematic to deny ssl.gstatic.com across the board, because that causes website breakage.
> The author confesses he did not know about his web browser phoning home to ssl.gstatic.com but titles his blog post about Little Snitch with the phrase "that nobody knows about" insinuating that he now knows about something that others do not.
This is a gross mischaracterization of the blog post, the title of which literally starts with "Little Snitch feature". I'm certain that nobody knew about the feature (matching an associated process with "via"), because the Little Snitch developers themselves weren't aware of it until they reviewed the implementation.
Little Snitch has remained closed source for over 23 years. As such, there will always be things about it that its authors know that "no one else knows", unless they choose to share. Why this non-transparency might matter to some computer users is a question left for the reader.