Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

KevinSR

macrumors newbie
Original poster
Feb 29, 2024
16
1
Hi, hope all are well.

I am a new Little Snitch user and would greatly appreciate some assistance with the settings. I'm on Sonoma 14.7.

What settings do I need to receive alerts for every connection? I think I messed something up and a bunch of connections I don't want are getting through with no alerts.

Thanks much!
 
You can either look at the "Little Snitch Rules" and delete the ones you think are wrong…or…just delete all the rules and start over.
Yes I noticed I can do that but that's after there's already been 30 unwanted connections for just visiting one site. I need to change the settings to ask for every connection.
 
LS > Settings > General > Operation Mode:

Select "Alert"

Screenshot 2024-10-25 at 18.27.27.png
 
I have been playing with Little Snitch over the last few days.

I remain extremely interested in using Little Snitch, but I fear that I lack the technical expertise to fully and properly implement and use it and may do more harm than good . Were I to use Little Snitch, I would like to have it completely and fully dialed in!

I am comfortable with its features set and settings but because I am not a security expert I have a number of questions.

Blocklists

a. There are so many alerts in respect of e-mails where the result of blocking the alert is that the e-mail may not properly display. Is there a block list that focuses on these to provide “comfort” that allowing the alerts that do not get blocked is a fair place to start?

b. What is the best practice in respect of Blocklists (i.e., don’t use, use, use and review, etc.)?



Blocked Webpage: There is a webpage that is i) blocked and ii) the domain does not appear in the rules. I am thinking that they it is blocked by the Blocklist I have installed or by a domain / rule that appeared in a previous alert (i.e., no alerts were received in respect of this website). How do I identify the rule that is blocking the webpage?


Configuration / Setup: As there ae so many domains – making it near impossible to review all of them:

a. What is the recommended configuration process (noting I selected the iCloud Services, macOS Services and Apple Apps Rule Services and then dealt with all the alerts from third parties)?

b. What is the recommended standard / test to be comfortable that the configuration is optimal given i) it is impossible to approve all rules ii) it is impossible (subject to the answers below) to definitively determine the purpose / use of a domain, whether to block the domain, hostname, IP Address, and more?



Network Monitor:

a. Settings > Privacy & Security > Location Services > Little Snitch Agent and Little Snitch Network Monitor are both enabled but my location is not being moved / set when selecting “Automatically determine my location”. How can this be fixed?


b. What is the best way to open Network Monitor (i.e., is there a way to open it other than clicking on the menu bar icon, I would have thought that it would appear under the Little Snitch > View menu)?



Profiles: I have three profiles setup (i.e., Away, Home/Office, and Effective in all profiles).

a. What is the best practice for setting up profiles (i.e., all rules in Effective in all profiles and then tweak the Away and Home/Office profile as needed)?


b. What is the best way to tweak the Away and Home/Office profiles (i.e., is it to copy the rules that differ from in Effective in all profiles to each of the Away and Home/Office profiles and then change /modify the rules in the Away and Home/Office profiles)?

c. How does one Allow the Local Network in the Home/Office profile but deny it in the Away profile?


Rules:

a. How does one decide (i.e., what are best practices between blocking a domain, a hostname, an IP address, and all the other options (i.e., port, protocols, etc.)?

b. Is it best practice / important to approve all rules given most / a large number of the rules com from Rule Groups (i.e., iCloud Services, macOS services, Apple and Apps)?


c. What is the best way to determine whether a domain / hostname / IP address should be denied as I find it very time consuming and not always helpful to Google each alert I get?


Start over

a. If one wants to start over based on having a better understanding is Little Snitch > File > Restore factory Defaults the preferred approach?



Little Snitch versus Little Snitch Mini

a. Given my knowledge level (or lack thereof as illustrated by the above) would you recommend Little Snitch or Little Snitch Mini noting I am an individual user (not part of a larger organization) and why?


Thank you.
 

I am following this thread looking for some insights as well. Your question will require quite an effort to answer since it is so exhaustive in scope.

I'll only contribute my approach. I just leave the app set to Silent Allow. I turn on a bunch of the predefined blocklists and let them handle the things I would have blocked by myself in the past (before Little Snitch included the functionality of predefined blocklists). For the most part, things just work. Now and again a website complains or doesn't display. When that happens, I temporarily turn off Little Snitch to see what I am missing.
 
  • Love
Reactions: splifingate
@svenmany, appreciate your response.

I understand your approach and was thinking about using an identical approach noting:

1. Approach you follow provides protection and is likely 90%+ of the job. If I am to use Little Snitch I want to understand what I am doing inclusive of a source to determine whether to block / not block a website. Things like Mail are difficult as they include all types of embedded information that **likely** collect information on us that will pass through your approach.

2. I got blocked from a website a use by one of the Block Lists. I need to understand hw to find out what embedded rule is blocking me. The problem is that back lists cannot be altered so I will need to try the Precedence route.

Trying to engage a thread party ti teach me but to may be more than I want to do, time wise. With that I will need to decide whether I do / do not want to use Little Snitch.

Worth noting, I am thinking what's the point of blocking the information on my MBP when my iPhone has no equivalent blocking capability?

Comments / thoughts?
 
Things like Mail are difficult as they include all types of embedded information that **likely** collect information on us that will pass through your approach.

Yeah. I use Fastmail and access their service using their browser-based application. I have it set to not load images (probably a misnomer since non-image things could be referenced). If I choose to load images in that web app, it loads them through their proxy. I do understand that's not good enough; links themselves could include personal information. So, I don't load images from senders I don't trust. But, even senders I trust want information about me and I just have to get over it.

2. I got blocked from a website a use by one of the Block Lists. I need to understand hw to find out what embedded rule is blocking me. The problem is that back lists cannot be altered so I will need to try the Precedence route.

In the Network Monitor you can show the addresses which were blocked over a chosen time frame. Then you can "Show Corresponding Rule" after right-clicking on one that interests you.

Worth noting, I am thinking what's the point of blocking the information on my MBP when my iPhone has no equivalent blocking capability?

You might consider VPN software for your phone. I know that ProtonVPN offers the ability to "Block malware, ads, & trackers". That's the setting I choose when I use that VPN.
 
In the Network Monitor you can show the addresses which were blocked over a chosen time frame. Then you can "Show Corresponding Rule" after right-clicking on one that interests you.

Appreciated, I will give that a try.

I think the issue will be that the rule will come from the Block List which means that I cannot override unless I gat set a rule to allow it which takes precedence.


You might consider VPN software for your phone. I know that ProtonVPN offers the ability to "Block malware, ads, & trackers". That's the setting I choose when I use that VPN.

I can / will look into it but I wonder whether it blocks / stops data collection like Little Snitch does.

If it does then why bother with Little Snitch as using a VPN wold be much easier!

That said, do uu know whether Proton VPN blocks / stops data collection like Little Snitch does?

Thank you.
 
I think the issue will be that the rule will come from the Block List which means that I cannot override unless I gat set a rule to allow it which takes precedence.

I have a feeling you'll run into problems with Little Snitch in terms of precedence. The biggest challenge I would face is that the online help for version 6 doesn't seem to discuss precedence. Version 5's help does. I'm not sure it they're the same, especially since version 5 didn't have blocklists. I would suggest contacting support to get clarity on what's possible before you purchase Little Snitch.


If it does then why bother with Little Snitch as using a VPN wold be much easier!


That said, do uu know whether Proton VPN blocks / stops data collection like Little Snitch does?

I would contact Proton to ask that question. I suspect they use one or more rulesets that Little Snitch offers.

Running a VPN all the time to achieve the same blocking that Little Snitch does introduces unrelated functionality into the mix; the VPN hides your IP address even when connections are allowed. A VPN has advantages and disadvantages. Increased privacy is an advantage. Throughput limitations and occasional problems making desired connections are disadvantages.
 
@svenmany I am focusing on i) work and ii) moving into my new MBP one the next few days but once done I will dig into the VPN more. I am thinking that may be the easiest solution of all. Stay tuned!
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.