[HN Gopher] Little Snitch feature nobody knows about
___________________________________________________________________
Little Snitch feature nobody knows about
Author : ingve
Score : 138 points
Date : 2025-01-24 14:18 UTC (8 hours ago)
(HTM) web link (lapcatsoftware.com)
(TXT) w3m dump (lapcatsoftware.com)
| dmvjs wrote:
| if Safari needs to use google as a search engine they
| (Google/Apple) might want to be able to track how many attempts
| were made vs successful, or to make sure its up and available
| (its never down right?), and I'd guess this check is a way to
| achieve that.
| reaperducer wrote:
| _if Safari needs to use google as a search engine they (Google
| /Apple) might want to be able to track how many attempts were
| made vs successful, or to make sure its up and available (its
| never down right?), and I'd guess this check is a way to
| achieve that._
|
| As a Little Snitch user, I'm glad to be able to tell both Apple
| and Google "None of your business."
|
| It's a simple little phrase that used to be very common, but
| people seem to have forgotten it over the last 30 years.
| lapcat wrote:
| Considering that the relevant preference key is
| WBSOfflineSearchSuggestionsModelLastUpdateDateKey, and the
| check occurs exactly once a week, your guess seems wrong.
| dinkblam wrote:
| _off-topic rant mode on_
|
| Little Snitch is awesome, but i had to stop using it at version 5
| because it can no longer be installed into a subfolder of the
| Applications folder.
|
| Mac apps are supposed to be usable from any location (even
| outside the /Applications/ folder) and i have used hundreds of
| apps from /Applications/_Apps/ since the Mac OS X Public Beta in
| 2000 without issue.
|
| Little Snitch >= 5.0 is the only one having problems here,
| despite supposedly being a "real native Mac app". what gives?
|
| _off-topic rant mode off_
| sbaildon wrote:
| How come you're nesting?
| dinkblam wrote:
| wanted to keep 3rd party and 1st party stuff separate.
|
| also makes copying all installed apps to another mac a
| 1-second thingie
| neurobashing wrote:
| on Sequoia, it's already separated. Apps shipped as part of
| the OS live in /System/Applications, and stuff you install
| (however you do it) are in /Applications.
| radicality wrote:
| What's meant to go under /Users/<username>/Applications ?
| If I'm the only user of the machine is there a difference
| between that and /Applications ?
|
| Looks like for me the only thing is Jetbrains IDEs
| installed themselves there hmm.
| neurobashing wrote:
| I think for the average user it's more of a remnant of
| NeXTStep. It is galling that Little Snitch doesn't let
| you use a supported feature; but I think Apple doesn't
| really care about ~/Applications any more, since they
| "solved" it w/ the Applications and System/Applications
| "split".
| behnamoh wrote:
| > NeXTStep
|
| That was 30 years ago! Why should Apple stick to a
| decades-long rule?
| AlanYx wrote:
| IMHO the best way to do this is to install apps in the
| Applications subfolder of your user directory. When you do
| this, Launchpad and everything else treats them as if they
| were installed in the /Applications folder, but it's still
| trivially easy to tell what you need to migrate to a new
| machine.
| LexGray wrote:
| - Typically third party apps require admin passwords to
| update when in the applications folder which is a pain for
| non admin users. - Sometimes it is nice to put apps in a
| users applications folder so other users do not have access
| (do not have other users games cluttering launchpad). -
| Sometimes you just want to put your utilities in the
| utilities folder.
| ryandrake wrote:
| That seems like such a bizarre restriction imposed by the app
| developer. They must have gone out of their way to stop this,
| because every application on my system can run from pretty much
| anywhere on my filesystem.
|
| It's as if a Windows developer decided their program should
| only be runnable from a directory under "Program Files". So
| weird! Do they provide an explanation on their web site for the
| change?
| iforgot22 wrote:
| Does it work if you put it in the subfolder then symlink into
| /Applications?
| lapcat wrote:
| Have you tried emailing the developer? As the article says,
| that's what I did.
| kstrauser wrote:
| I shan't be denied my right to wildly speculate.
| detourdog wrote:
| I think it might be a security thing. The Mach kernel uses full
| file paths at the heart of the system. They may be relying on
| Apple maintaining the Application folder integrity. If that
| allowed running from other locations it becomes harder to
| insure the integrity of binary running.
| nerflad wrote:
| Anecdote: This became a problem for me with several apps after
| installing Sequoia
| amendegree wrote:
| Someone created a similar extension for chrome called little
| rat[0], it needs to be installed in developer mode bec chrome
| doesn't allow extensions to interact with each normally.
|
| [0] https://github.com/dnakov/little-rat?tab=readme-ov-file
| noahjk wrote:
| I was using a similar extension which whitelisted / blacklisted
| IP addresses in Chrome. I had it set to blacklist my home IP,
| which I paired with an in-browser VPN app. Since Chrome's
| latest extension update (about 3 weeks now?), I've had Chrome
| send requests to pages which were open before the extension
| loaded, leaking my IP. I assume similar issues could happen
| extension-to-extension, so this shouldn't be used for any
| privacy-related reasons - can't trust a Chrome extension to
| block 100% of anything.
| hk1337 wrote:
| It's been some time since I have used Little Snitch and I never
| really got all that deep into it, so what I am thinking may
| already exist.
|
| It would be nice if you could import a text or config file of
| standard things to allow/block. A general format that people
| could post, fork, edit, their own variations. Something akin to
| stevenblack/hosts providing a base list of hosts to block but the
| list is categorized as well as could be customized.
|
| Another, probably better example, is something that could be
| saved in a dotfiles repository. You can share it with others but
| also if/when you need to setup a new computer, you don't have to
| start have completely fresh with Little Snitch.
| lapcat wrote:
| It does have this now, blocklists:
| https://help.obdev.at/littlesnitch6/concepts-blocklists
| rustc wrote:
| If using Google Fonts without explicit informed consent is a GDPR
| violation then this surely is too?
| tom1337 wrote:
| You've probably agreed to that somewhere in the Terms Of
| Service and therfore gave consent
| lcnPylGDnU4H9OF wrote:
| It seems GDPR authorities don't think like that. There's
| probably a reason OP included "informed" in their comment.
| rustc wrote:
| From what I've read online, that would not be enough.
|
| According to https://gdpr-info.eu/issues/consent/
|
| > Consent must be freely given, specific, informed and
| unambiguous. In order to obtain freely given consent, it must
| be given on a voluntary basis. The element "free" implies a
| real choice by the data subject. Any element of inappropriate
| pressure or influence which could affect the outcome of that
| choice renders the consent invalid.
|
| Declining terms of service will affect the outcome so it
| can't be considered "freely given consent".
| cipehr wrote:
| I haven't used little snitch in nearly 15 years... I love all the
| security focused apps that objective-see puts out, and they have
| a Little Snitch equivalent "LuLu".
|
| Does anyone know if the same thing can be achieved with LuLu?
| https://objective-see.org/products/lulu.html It looks like it can
| but I haven't used it yet.
| zikduruqe wrote:
| You can go to settings and then lists to put in your custom
| blocklists.
| magic_smoke_ee wrote:
| Then you don't have control or visibility over Apple or third-
| party apps sending analytics likely without your approval.
|
| LuLu has a fatal flaw: it drops or closes TCP connections
| randomly resulting in dropped SSH sessions. No amount of TCP
| keepalives on the client- or server-side will resolve this.
| This makes it a non-starter for anyone doing anything real.
|
| Also good:
|
| - BlockBlock - disk access application "firewalling" on top of
| macOS'es privacy & security settings is very good
|
| - RansomWhere? - ransomware process mass file change
| interception
|
| - ReiKey - input interception monitor
|
| - ProcessMonitor, DNSMonitor, FileMonitor, TaskExplorer,
| KextViewer, NetIQuette, Dylib Hijack Scanner, KnockKnock
|
| - Oversight - webcam and audio hijack monitor (although I use
| ancient EOL Growl + Hardware Growl just to catch hardware
| events too)
|
| - No longer useful or usable: Do Not Disturb, LuLu
| hernantz wrote:
| Is there a similar software for linux?
| perihelions wrote:
| OpenSnitch
|
| https://hn.algolia.com/?query=opensnitch&type=all
| kreyenborgi wrote:
| I use this. The first week was weird and scary until I had
| accepted the rules I needed for my daily usage, now it's been
| weeks since it's said anything (and I had to check that it
| was still running but it is).
|
| E.g. running the android emulator was enlightening :-S
| jazzyjackson wrote:
| This looks similar, Safing Portmaster
|
| https://github.com/safing/portmaster
| kylehotchkiss wrote:
| Interesting! I see this not so much as a feature people would use
| to make their own rules but a good feature for those creating
| lists of rules, like in this case "Un-Google my Mac"
| OptionOfT wrote:
| I currently don't have a Mac, but could we do an MITM inspection
| to see what is requested and responded?
|
| Since this is a Google domain I wonder if Apple pins the
| certificates.
|
| I am currently battling a bug on iOS where blocking
| mask.icloud.com & mask-h2.icloud.com leads to Mail 'checking for
| email' for a long time. But I can't inspect what is requested.
| And supposedly, this is the way to prevent iCloud relay:
| https://developer.apple.com/icloud/prepare-your-network-for-...
| lapcat wrote:
| Do you have Protect Mail Activity or Hide IP Address enabled in
| Mail Privacy Protection Settings?
| OptionOfT wrote:
| No. That's all disabled. In fact, after x minutes the mail
| comes in.
|
| Also, I tried replying with NOERROR and NXDOMAIN. Neither
| work.
| MaxwellsDaemon wrote:
| My guess was a favicon for the search window
| lapcat wrote:
| What search window?
| fmajid wrote:
| It could also be downloading the database of known malicious
| sites from Google Safe Browsing:
|
| https://transparencyreport.google.com/safe-browsing/overview
| lapcat wrote:
| No, that's safebrowsing.googleapis.com
| philsnow wrote:
| I had thought that maybe it was pre-warming a connection so that
| when the user searches for something, it saves a network round
| trip and seems faster, but probably not if it's to a static
| domain.
| 1vuio0pswjnm7 wrote:
| It's amusing to hear of a software developer just beginning to
| block ssl.gstatic.com in 2025 when other folks have been denying
| access to ssl.gstatic.com and various other unnecessary domains
| for many years, years before Little Snitch even existed. The
| author confesses he did not know about his web browser phoning
| home to ssl.gstatic.com but titles his blog post about Little
| Snitch with the phrase "that nobody knows about" insinuating that
| he now knows about something that others do not. Funny.
| fragmede wrote:
| https://xkcd.com/1053/
| lapcat wrote:
| > years before Little Snitch even existed
|
| Little Snitch was first released in 2003. Unfortunately, your
| comment is a stereotypical example of the worst of Hacker News,
| both condescending _and_ ignorant.
|
| In any case, it's unclear exactly which version of Safari
| and/or macOS started the specific behavior noted in the blog
| post. Moreover, as the blog post also notes, it's problematic
| to deny ssl.gstatic.com across the board, because that causes
| website breakage.
|
| > The author confesses he did not know about his web browser
| phoning home to ssl.gstatic.com but titles his blog post about
| Little Snitch with the phrase "that nobody knows about"
| insinuating that he now knows about something that others do
| not.
|
| This is a gross mischaracterization of the blog post, the title
| of which literally starts with "Little Snitch feature". I'm
| certain that nobody knew about the feature (matching an
| associated process with "via"), because the Little Snitch
| developers themselves weren't aware of it until they reviewed
| the implementation.
| midtake wrote:
| > The trick is to use "via" in the Little Snitch rule. When
| you're creating the rules, enter the full file paths of the two
| processes, separated by "via".
|
| Everyone who has used homebrew knows this one.
| KORraN wrote:
| Well, here's me, so not everyone.
| lapcat wrote:
| Was this supposed to be a joke? It's not a good joke.
___________________________________________________________________
(page generated 2025-01-24 23:01 UTC)