Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Pirating the Pirates (mubi.com)
    22comments
  2. Hijacking the PS5's RTMP Stream (yashgarg.dev)
    4comments
  3. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    115comments
  4. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    8comments
  5. What Heraldry and Mon Can Teach Us About Building Visual-Identity Generators (benovermyer.com)
    12comments
  6. MongoDB CEO resigns to join Meta (reuters.com)
    132comments
  7. The problem is not AI code, but not knowing about system architecture or intent (ssp.sh)
    161comments
  8. Driver Ticketed for No Insurance Just Because Flock (YC 2017) Said She Didn't (techdirt.com)
    3comments
  9. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    4comments
  10. 13 Months Sober (2025) (bobbytables.io)
    40comments
  11. Coding Is Not Solved (alexewerlof.com)
    310comments
  12. 37,500 border drawings: a map of the world as people remember it (habibicode.org)
    31comments
  13. Show HN: PaperMono, e-ink fridge magnet shopping list with mobile web page (github.com/seamusc)
    37comments
  14. What Would a Serious AI Product Look Like? (glyph.im)
    20comments
  15. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    79comments
  16. Solving a corn puzzle with CP-SAT (thill.me)
    2comments
  17. OpenAI still doesn't seem to have a handle on all of its rogue AI activity (techcrunch.com)
    —discuss
  18. Owed a billion dollars in Nvidia stock (colo.to)
    421comments
  19. Footguns with Postgres "at time zone 'UTC'" (bookofrevenue.com)
    75comments
  20. Show HN: Hntui – A TUI for Hacker News (github.com/ahmd-sh)
    49comments
  21. Ember-1 (fireworks.ai)
    241comments
  22. When did Google get so weird? (sancho.bearblog.dev)
    903comments
  23. Nissan's third generation e-POWER powertrain (nissan-global.com)
    312comments
  24. Show HN: Free alternative to graphics design giants (scissor.studio)
    18comments
  25. Thinking fast and slow in AI: The role of metacognition (2021) (arxiv.org)
    65comments
  26. How Pew Research Center is – and is not – using AI in our work (pewresearch.org)
    2comments
  27. Self-Hosting on the Dark Web (alvarezrosa.com)
    106comments
  28. Malleable software: Restoring user agency in a world of locked-down apps (2025) (inkandswitch.com)
    69comments
  29. Alan Kay's answer to “Did the ENIAC have a BIOS”? (quora.com)
    61comments
  30. Guitar amp and effects pedal built on the Waveshare ESP32-S3-Touch-AMOLED-2.06 (github.com/dashersw)
    74comments

Little Snitch “denied” connections leak your IP address

57 pointsby 3y agolapcatsoftware.com
10 comments
3y agoHN ↗

allows you can modulate a signal onto connection attempts to bypass little snitch entirely!

3y agoHN ↗

wow, that is absurdly careless. I paid money for little snitch and I am incredibly disappointed and feel a huge loss of trust, I trusted Little Snitch to keep me safe from things I consider harmful and now it comes out they don't care about privacy at all.

3y agoHN ↗

Not a little snitch user, however I do happen to agree with the author that they should disclose this somewhere.

A quick Google search and some viewing of Objective Development's help center doesn't show any related results. Amusingly, it's the author's post and the other article mentioned that take top slot.

As for remediations, the difficult but proper implementation would be to intercept, but handle the TCP handshake and emulate the responses in order to get the SNI. The easy way is to just add a behavior toggle with an explanation of the caveats.

3y agoHN ↗

I have noticed this on my local Pi-Hole — that Little Snitch denials still result in a DNS resolution (i.e. requested hostname still has IP resolved).

To every person I've watched DENY a connection via LittleSnitch popup, I have been told "you don't know what you're talking about — why would it behave like that?!"

It just does. You need your own network DNS and firewalls, and you need to know how to use them.

3y agoHN ↗

This is such a stupid design decision, especially for the blocked processed, very disappointed in Little Snitch, and what's worse is that it seems the alternatives are not better :(

3y agoHN ↗

I don't understand the negativity in here. I would never expect Little Snitch (my opinion) to completely block all network traffic on all levels and this seems reasonable to me. Does it leak my ip? Yes. Do I think it compromises my security? No, there's so much noise on internet facing services that just initiating connection would easily get lost in the noise of all the botnets, port scans and legitimate users.

There's huge amount of other ways how data can be exfiltrated if one wishes to do so, from domain fronting, DNS level (you can easily tunnel data via DNS), forcing OS and/or whitelisted application to do it on your behalf (haven't tried but I think the files where rules are stored is readable by current user/process?). Such techniques can bypass even insanely expensive network IDS taps if there is enough incentive on the attacker side. I would never expect Little Snitch to be on the same level as those expensive network taps.

I think the use case people now forget is preventing applications to send meaningful data to analytic services like google ad-sense and similar or sending full data payloads (like http body). For this it's good enough. If your worry is about advanced techniques that would exfiltrate the data via DNS tunneling, partial TCP handshakes or forcing to do the connection/beacon on OS level for you then Little Snitch isn't going to help you and your problem is somewhere else. The last Electron wrapped application you downloaded that is packed with 5+ ad services isn't going to do that so it can get your IP.

On the other hand the wording may have been changed slightly and their use of "data" word so it doesn't give user the wrong impression but there is also a balance between explaining in 1-2 sentences what it does and writing 20 page document just to explain that and be technically correct in every word.

3y agoHN ↗

I would never expect Little Snitch (my opinion) to completely block all network traffic on all levels

It's very easy to say this in retrospect, having read the blog post. How many people would have said it beforehand?

As far as I can tell, hardly anyone has ever said it, except the one other mentioned article from 2021: https://rhinosecuritylabs.com/network-security/bypassing-lit...

Moreover, it seems that Little Snitch changed its behavior at some point in order to use deep packet inspection. It wasn't always that way.

3y agoHN ↗

Is this due to a limitation in MacOS?