LittleSnitch does tell you when LittleSnitch and MicroSwitch phone home (auto-update checks only as far as I've seen), but they're the same developers so theoretically if one could fake one, one could fake both: they could be tightly coupled.
So you have to implicitly trust the ObDev guys, and you have to implicitly trust the hardware, but beyond those two assumptions they function great for any other threat models.
Would still be nice if they were both open source but hey: I use the open source vscode and it phones home uncontrollably all the time, so source code only benefits us so much.
Agreed. I replied in a sibling[0], which I think is relevant here. It seems I should definitely queue looking into what testing has been publicly done, etc. and collate that.
>Would still be nice if they were both open source but hey: I use the open source vscode and it phones home uncontrollably all the time, so source code only benefits us so much
Interesting thought. I would assume some audits have been done via blackbox testing of some sort (e.g. hardware monitor, routing all traffic through a proxy and logging it, etc.) by some infosec group/Co, but I also haven’t researched that.
I think there was a talk on breaking LittleSnitch at either Defcon or B-sides a few years back. I couldn't get in though; it was full. Whatever it was is probably fixed by now anyway.