Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I got MicroSnitch as part of a bundle with LittleSnitch, without really knowing what it was at the time. When I figured it out, I had the same thought as you.

It's definitely not something I'd ever trust completely, not only could it be spying on you, but I also don't really trust my hardware. However, I must say, it's still very nice to have. It at least narrows the possible spying vectors, and it's nice to know immediately what apps are listening; the best example being Android Studio emulator: always listening.



Wouldn’t LittleSnitch be ideal in this situation to assist in checking if MicroSnitch is phoning home?


LittleSnitch does tell you when LittleSnitch and MicroSwitch phone home (auto-update checks only as far as I've seen), but they're the same developers so theoretically if one could fake one, one could fake both: they could be tightly coupled.

So you have to implicitly trust the ObDev guys, and you have to implicitly trust the hardware, but beyond those two assumptions they function great for any other threat models.

Would still be nice if they were both open source but hey: I use the open source vscode and it phones home uncontrollably all the time, so source code only benefits us so much.


Agreed. I replied in a sibling[0], which I think is relevant here. It seems I should definitely queue looking into what testing has been publicly done, etc. and collate that.

>Would still be nice if they were both open source but hey: I use the open source vscode and it phones home uncontrollably all the time, so source code only benefits us so much

Yup; definitely true.

[0]: https://news.ycombinator.com/item?id=18201533


Who knows if LittleSnitch is not a "social hack" by itself ?


Interesting thought. I would assume some audits have been done via blackbox testing of some sort (e.g. hardware monitor, routing all traffic through a proxy and logging it, etc.) by some infosec group/Co, but I also haven’t researched that.


I think there was a talk on breaking LittleSnitch at either Defcon or B-sides a few years back. I couldn't get in though; it was full. Whatever it was is probably fixed by now anyway.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: