Need to develop on insecure wifi? Use protection
github.com
github.com
Rather than having alerting for connections to services which provide remote access (assuming authenticated using vulnerabilities or defaults), you should evaluate if you need your laptop running an FTP server or whatever other service. And if you do, firewalling that off or only enabling the service when in use.
If you need certificate pinning on insecure wifi, then you need it everywhere.
I have it set to deny everything except openvpn, Captive Network Assistant and UserEventAgent on all networks by default. Only explicitly whitelisted networks have access beyond these three rules.
On an untrusted network (the default state), you can still connect to public wifi (using the Captive Network Assistant and UserEventAgent), and once connected to the insecure wifi, connect to the secure VPN. The VPN connection is whitelisted, so once it has connected to VPN everything starts flowing again.
As soon as I disconnect from the VPN no traffic goes in or out.
Couldn't imagine using public wifi at airports, or coffee shops without it now.
Restricts network access similarly to Little Snitch, but can also restrict file system access.
No affiliation with either. I've used (and would recommend) both, but the additional functionality in Hands Off! is useful for me.
I agree though, that setting up a firewall would be much more effective. Alternatively, disable password authentication in OpenSSH and just use keypairs. But why exactly would you be running any of those services on your Mac anyway? As far as I know, these forms of remote access are disabled by default on OSX (for good reason).