Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Definitely not Windows (Win 11 parody) (definitelynotwindows.com)
    49comments
  2. So long Google, and thanks for all the nudes (lecaro.me)
    20comments
  3. Pirating the Pirates (mubi.com)
    59comments
  4. GrapheneOS – When an App Is Slow (wirelessmoves.com)
    —discuss
  5. Hijacking the PS5's RTMP Stream (yashgarg.dev)
    16comments
  6. Claude Sonnet 5.5 (anthropic.com)
    138comments
  7. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    17comments
  8. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    124comments
  9. Launch HN: Vespper (YC F24) – SOTA Docx MCP (vespper.com)
    2comments
  10. Who Wrote Elizabeth I's Most Scathing Letters? (smithsonianmag.com)
    1comments
  11. When did Google get so weird? (sancho.bearblog.dev)
    942comments
  12. The Teen Portraits That Captivated Sofia Coppola (newyorker.com)
    1comments
  13. What Heraldry and Mon Can Teach Us About Building Visual-Identity Generators (benovermyer.com)
    13comments
  14. MongoDB CEO resigns to join Meta (reuters.com)
    180comments
  15. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    17comments
  16. I made a visual workspace for AI Automations (biom.dev)
    9comments
  17. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    93comments
  18. 37,500 border drawings: a map of the world as people remember it (habibicode.org)
    31comments
  19. OpenAI still doesn't seem to have a handle on all of its rogue AI activity (techcrunch.com)
    60comments
  20. Coding Is Not Solved (alexewerlof.com)
    352comments
  21. The problem is not AI code, but not knowing about system architecture or intent (ssp.sh)
    191comments
  22. What Would a Serious AI Product Look Like? (glyph.im)
    25comments
  23. Footguns with Postgres “at time zone 'UTC'” (bookofrevenue.com)
    85comments
  24. Solving a corn puzzle with CP-SAT (thill.me)
    4comments
  25. Show HN: PaperMono, e-ink fridge magnet shopping list with mobile web page (github.com/seamusc)
    48comments
  26. Owed a billion dollars in Nvidia stock (colo.to)
    427comments
  27. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    6comments
  28. Show HN: Free alternative to graphics design giants (scissor.studio)
    31comments
  29. Ember-1 (fireworks.ai)
    243comments
  30. Nissan's third generation e-POWER powertrain (nissan-global.com)
    335comments

Little Snitch “denied” connections leak your IP address

57 pointsby 3y agolapcatsoftware.com
10 comments
3y agoHN ↗

allows you can modulate a signal onto connection attempts to bypass little snitch entirely!

3y agoHN ↗

wow, that is absurdly careless. I paid money for little snitch and I am incredibly disappointed and feel a huge loss of trust, I trusted Little Snitch to keep me safe from things I consider harmful and now it comes out they don't care about privacy at all.

3y agoHN ↗

Not a little snitch user, however I do happen to agree with the author that they should disclose this somewhere.

A quick Google search and some viewing of Objective Development's help center doesn't show any related results. Amusingly, it's the author's post and the other article mentioned that take top slot.

As for remediations, the difficult but proper implementation would be to intercept, but handle the TCP handshake and emulate the responses in order to get the SNI. The easy way is to just add a behavior toggle with an explanation of the caveats.

3y agoHN ↗

I have noticed this on my local Pi-Hole — that Little Snitch denials still result in a DNS resolution (i.e. requested hostname still has IP resolved).

To every person I've watched DENY a connection via LittleSnitch popup, I have been told "you don't know what you're talking about — why would it behave like that?!"

It just does. You need your own network DNS and firewalls, and you need to know how to use them.

3y agoHN ↗

This is such a stupid design decision, especially for the blocked processed, very disappointed in Little Snitch, and what's worse is that it seems the alternatives are not better :(

3y agoHN ↗

I don't understand the negativity in here. I would never expect Little Snitch (my opinion) to completely block all network traffic on all levels and this seems reasonable to me. Does it leak my ip? Yes. Do I think it compromises my security? No, there's so much noise on internet facing services that just initiating connection would easily get lost in the noise of all the botnets, port scans and legitimate users.

There's huge amount of other ways how data can be exfiltrated if one wishes to do so, from domain fronting, DNS level (you can easily tunnel data via DNS), forcing OS and/or whitelisted application to do it on your behalf (haven't tried but I think the files where rules are stored is readable by current user/process?). Such techniques can bypass even insanely expensive network IDS taps if there is enough incentive on the attacker side. I would never expect Little Snitch to be on the same level as those expensive network taps.

I think the use case people now forget is preventing applications to send meaningful data to analytic services like google ad-sense and similar or sending full data payloads (like http body). For this it's good enough. If your worry is about advanced techniques that would exfiltrate the data via DNS tunneling, partial TCP handshakes or forcing to do the connection/beacon on OS level for you then Little Snitch isn't going to help you and your problem is somewhere else. The last Electron wrapped application you downloaded that is packed with 5+ ad services isn't going to do that so it can get your IP.

On the other hand the wording may have been changed slightly and their use of "data" word so it doesn't give user the wrong impression but there is also a balance between explaining in 1-2 sentences what it does and writing 20 page document just to explain that and be technically correct in every word.

3y agoHN ↗

I would never expect Little Snitch (my opinion) to completely block all network traffic on all levels

It's very easy to say this in retrospect, having read the blog post. How many people would have said it beforehand?

As far as I can tell, hardly anyone has ever said it, except the one other mentioned article from 2021: https://rhinosecuritylabs.com/network-security/bypassing-lit...

Moreover, it seems that Little Snitch changed its behavior at some point in order to use deep packet inspection. It wasn't always that way.

3y agoHN ↗

Is this due to a limitation in MacOS?