[HN Gopher] Little Snitch feature nobody knows about
       ___________________________________________________________________
        
       Little Snitch feature nobody knows about
        
       Author : ingve
       Score  : 138 points
       Date   : 2025-01-24 14:18 UTC (8 hours ago)
        
 (HTM) web link (lapcatsoftware.com)
 (TXT) w3m dump (lapcatsoftware.com)
        
       | dmvjs wrote:
       | if Safari needs to use google as a search engine they
       | (Google/Apple) might want to be able to track how many attempts
       | were made vs successful, or to make sure its up and available
       | (its never down right?), and I'd guess this check is a way to
       | achieve that.
        
         | reaperducer wrote:
         | _if Safari needs to use google as a search engine they (Google
         | /Apple) might want to be able to track how many attempts were
         | made vs successful, or to make sure its up and available (its
         | never down right?), and I'd guess this check is a way to
         | achieve that._
         | 
         | As a Little Snitch user, I'm glad to be able to tell both Apple
         | and Google "None of your business."
         | 
         | It's a simple little phrase that used to be very common, but
         | people seem to have forgotten it over the last 30 years.
        
         | lapcat wrote:
         | Considering that the relevant preference key is
         | WBSOfflineSearchSuggestionsModelLastUpdateDateKey, and the
         | check occurs exactly once a week, your guess seems wrong.
        
       | dinkblam wrote:
       | _off-topic rant mode on_
       | 
       | Little Snitch is awesome, but i had to stop using it at version 5
       | because it can no longer be installed into a subfolder of the
       | Applications folder.
       | 
       | Mac apps are supposed to be usable from any location (even
       | outside the /Applications/ folder) and i have used hundreds of
       | apps from /Applications/_Apps/ since the Mac OS X Public Beta in
       | 2000 without issue.
       | 
       | Little Snitch >= 5.0 is the only one having problems here,
       | despite supposedly being a "real native Mac app". what gives?
       | 
       |  _off-topic rant mode off_
        
         | sbaildon wrote:
         | How come you're nesting?
        
           | dinkblam wrote:
           | wanted to keep 3rd party and 1st party stuff separate.
           | 
           | also makes copying all installed apps to another mac a
           | 1-second thingie
        
             | neurobashing wrote:
             | on Sequoia, it's already separated. Apps shipped as part of
             | the OS live in /System/Applications, and stuff you install
             | (however you do it) are in /Applications.
        
               | radicality wrote:
               | What's meant to go under /Users/<username>/Applications ?
               | If I'm the only user of the machine is there a difference
               | between that and /Applications ?
               | 
               | Looks like for me the only thing is Jetbrains IDEs
               | installed themselves there hmm.
        
               | neurobashing wrote:
               | I think for the average user it's more of a remnant of
               | NeXTStep. It is galling that Little Snitch doesn't let
               | you use a supported feature; but I think Apple doesn't
               | really care about ~/Applications any more, since they
               | "solved" it w/ the Applications and System/Applications
               | "split".
        
               | behnamoh wrote:
               | > NeXTStep
               | 
               | That was 30 years ago! Why should Apple stick to a
               | decades-long rule?
        
             | AlanYx wrote:
             | IMHO the best way to do this is to install apps in the
             | Applications subfolder of your user directory. When you do
             | this, Launchpad and everything else treats them as if they
             | were installed in the /Applications folder, but it's still
             | trivially easy to tell what you need to migrate to a new
             | machine.
        
           | LexGray wrote:
           | - Typically third party apps require admin passwords to
           | update when in the applications folder which is a pain for
           | non admin users. - Sometimes it is nice to put apps in a
           | users applications folder so other users do not have access
           | (do not have other users games cluttering launchpad). -
           | Sometimes you just want to put your utilities in the
           | utilities folder.
        
         | ryandrake wrote:
         | That seems like such a bizarre restriction imposed by the app
         | developer. They must have gone out of their way to stop this,
         | because every application on my system can run from pretty much
         | anywhere on my filesystem.
         | 
         | It's as if a Windows developer decided their program should
         | only be runnable from a directory under "Program Files". So
         | weird! Do they provide an explanation on their web site for the
         | change?
        
         | iforgot22 wrote:
         | Does it work if you put it in the subfolder then symlink into
         | /Applications?
        
         | lapcat wrote:
         | Have you tried emailing the developer? As the article says,
         | that's what I did.
        
           | kstrauser wrote:
           | I shan't be denied my right to wildly speculate.
        
         | detourdog wrote:
         | I think it might be a security thing. The Mach kernel uses full
         | file paths at the heart of the system. They may be relying on
         | Apple maintaining the Application folder integrity. If that
         | allowed running from other locations it becomes harder to
         | insure the integrity of binary running.
        
         | nerflad wrote:
         | Anecdote: This became a problem for me with several apps after
         | installing Sequoia
        
       | amendegree wrote:
       | Someone created a similar extension for chrome called little
       | rat[0], it needs to be installed in developer mode bec chrome
       | doesn't allow extensions to interact with each normally.
       | 
       | [0] https://github.com/dnakov/little-rat?tab=readme-ov-file
        
         | noahjk wrote:
         | I was using a similar extension which whitelisted / blacklisted
         | IP addresses in Chrome. I had it set to blacklist my home IP,
         | which I paired with an in-browser VPN app. Since Chrome's
         | latest extension update (about 3 weeks now?), I've had Chrome
         | send requests to pages which were open before the extension
         | loaded, leaking my IP. I assume similar issues could happen
         | extension-to-extension, so this shouldn't be used for any
         | privacy-related reasons - can't trust a Chrome extension to
         | block 100% of anything.
        
       | hk1337 wrote:
       | It's been some time since I have used Little Snitch and I never
       | really got all that deep into it, so what I am thinking may
       | already exist.
       | 
       | It would be nice if you could import a text or config file of
       | standard things to allow/block. A general format that people
       | could post, fork, edit, their own variations. Something akin to
       | stevenblack/hosts providing a base list of hosts to block but the
       | list is categorized as well as could be customized.
       | 
       | Another, probably better example, is something that could be
       | saved in a dotfiles repository. You can share it with others but
       | also if/when you need to setup a new computer, you don't have to
       | start have completely fresh with Little Snitch.
        
         | lapcat wrote:
         | It does have this now, blocklists:
         | https://help.obdev.at/littlesnitch6/concepts-blocklists
        
       | rustc wrote:
       | If using Google Fonts without explicit informed consent is a GDPR
       | violation then this surely is too?
        
         | tom1337 wrote:
         | You've probably agreed to that somewhere in the Terms Of
         | Service and therfore gave consent
        
           | lcnPylGDnU4H9OF wrote:
           | It seems GDPR authorities don't think like that. There's
           | probably a reason OP included "informed" in their comment.
        
           | rustc wrote:
           | From what I've read online, that would not be enough.
           | 
           | According to https://gdpr-info.eu/issues/consent/
           | 
           | > Consent must be freely given, specific, informed and
           | unambiguous. In order to obtain freely given consent, it must
           | be given on a voluntary basis. The element "free" implies a
           | real choice by the data subject. Any element of inappropriate
           | pressure or influence which could affect the outcome of that
           | choice renders the consent invalid.
           | 
           | Declining terms of service will affect the outcome so it
           | can't be considered "freely given consent".
        
       | cipehr wrote:
       | I haven't used little snitch in nearly 15 years... I love all the
       | security focused apps that objective-see puts out, and they have
       | a Little Snitch equivalent "LuLu".
       | 
       | Does anyone know if the same thing can be achieved with LuLu?
       | https://objective-see.org/products/lulu.html It looks like it can
       | but I haven't used it yet.
        
         | zikduruqe wrote:
         | You can go to settings and then lists to put in your custom
         | blocklists.
        
         | magic_smoke_ee wrote:
         | Then you don't have control or visibility over Apple or third-
         | party apps sending analytics likely without your approval.
         | 
         | LuLu has a fatal flaw: it drops or closes TCP connections
         | randomly resulting in dropped SSH sessions. No amount of TCP
         | keepalives on the client- or server-side will resolve this.
         | This makes it a non-starter for anyone doing anything real.
         | 
         | Also good:
         | 
         | - BlockBlock - disk access application "firewalling" on top of
         | macOS'es privacy & security settings is very good
         | 
         | - RansomWhere? - ransomware process mass file change
         | interception
         | 
         | - ReiKey - input interception monitor
         | 
         | - ProcessMonitor, DNSMonitor, FileMonitor, TaskExplorer,
         | KextViewer, NetIQuette, Dylib Hijack Scanner, KnockKnock
         | 
         | - Oversight - webcam and audio hijack monitor (although I use
         | ancient EOL Growl + Hardware Growl just to catch hardware
         | events too)
         | 
         | - No longer useful or usable: Do Not Disturb, LuLu
        
       | hernantz wrote:
       | Is there a similar software for linux?
        
         | perihelions wrote:
         | OpenSnitch
         | 
         | https://hn.algolia.com/?query=opensnitch&type=all
        
           | kreyenborgi wrote:
           | I use this. The first week was weird and scary until I had
           | accepted the rules I needed for my daily usage, now it's been
           | weeks since it's said anything (and I had to check that it
           | was still running but it is).
           | 
           | E.g. running the android emulator was enlightening :-S
        
         | jazzyjackson wrote:
         | This looks similar, Safing Portmaster
         | 
         | https://github.com/safing/portmaster
        
       | kylehotchkiss wrote:
       | Interesting! I see this not so much as a feature people would use
       | to make their own rules but a good feature for those creating
       | lists of rules, like in this case "Un-Google my Mac"
        
       | OptionOfT wrote:
       | I currently don't have a Mac, but could we do an MITM inspection
       | to see what is requested and responded?
       | 
       | Since this is a Google domain I wonder if Apple pins the
       | certificates.
       | 
       | I am currently battling a bug on iOS where blocking
       | mask.icloud.com & mask-h2.icloud.com leads to Mail 'checking for
       | email' for a long time. But I can't inspect what is requested.
       | And supposedly, this is the way to prevent iCloud relay:
       | https://developer.apple.com/icloud/prepare-your-network-for-...
        
         | lapcat wrote:
         | Do you have Protect Mail Activity or Hide IP Address enabled in
         | Mail Privacy Protection Settings?
        
           | OptionOfT wrote:
           | No. That's all disabled. In fact, after x minutes the mail
           | comes in.
           | 
           | Also, I tried replying with NOERROR and NXDOMAIN. Neither
           | work.
        
       | MaxwellsDaemon wrote:
       | My guess was a favicon for the search window
        
         | lapcat wrote:
         | What search window?
        
       | fmajid wrote:
       | It could also be downloading the database of known malicious
       | sites from Google Safe Browsing:
       | 
       | https://transparencyreport.google.com/safe-browsing/overview
        
         | lapcat wrote:
         | No, that's safebrowsing.googleapis.com
        
       | philsnow wrote:
       | I had thought that maybe it was pre-warming a connection so that
       | when the user searches for something, it saves a network round
       | trip and seems faster, but probably not if it's to a static
       | domain.
        
       | 1vuio0pswjnm7 wrote:
       | It's amusing to hear of a software developer just beginning to
       | block ssl.gstatic.com in 2025 when other folks have been denying
       | access to ssl.gstatic.com and various other unnecessary domains
       | for many years, years before Little Snitch even existed. The
       | author confesses he did not know about his web browser phoning
       | home to ssl.gstatic.com but titles his blog post about Little
       | Snitch with the phrase "that nobody knows about" insinuating that
       | he now knows about something that others do not. Funny.
        
         | fragmede wrote:
         | https://xkcd.com/1053/
        
         | lapcat wrote:
         | > years before Little Snitch even existed
         | 
         | Little Snitch was first released in 2003. Unfortunately, your
         | comment is a stereotypical example of the worst of Hacker News,
         | both condescending _and_ ignorant.
         | 
         | In any case, it's unclear exactly which version of Safari
         | and/or macOS started the specific behavior noted in the blog
         | post. Moreover, as the blog post also notes, it's problematic
         | to deny ssl.gstatic.com across the board, because that causes
         | website breakage.
         | 
         | > The author confesses he did not know about his web browser
         | phoning home to ssl.gstatic.com but titles his blog post about
         | Little Snitch with the phrase "that nobody knows about"
         | insinuating that he now knows about something that others do
         | not.
         | 
         | This is a gross mischaracterization of the blog post, the title
         | of which literally starts with "Little Snitch feature". I'm
         | certain that nobody knew about the feature (matching an
         | associated process with "via"), because the Little Snitch
         | developers themselves weren't aware of it until they reviewed
         | the implementation.
        
       | midtake wrote:
       | > The trick is to use "via" in the Little Snitch rule. When
       | you're creating the rules, enter the full file paths of the two
       | processes, separated by "via".
       | 
       | Everyone who has used homebrew knows this one.
        
         | KORraN wrote:
         | Well, here's me, so not everyone.
        
         | lapcat wrote:
         | Was this supposed to be a joke? It's not a good joke.
        
       ___________________________________________________________________
       (page generated 2025-01-24 23:01 UTC)