Little Snitch for Linux

Objective Development has released Little Snitch for Linux — the Linux version of its well-known tool for monitoring outgoing network connections, previously mostly available to macOS users. The new variant is positioned not as a strict security tool, but as a privacy control tool: it shows which applications are connecting to which nodes over the network, allows blocking unwanted connections, and tracks the history of network activity.

At the core of Little Snitch for Linux is eBPF, and the interface is designed as a local web UI, accessible at http://localhost:3031/. This approach not only allows monitoring current and past connections but also sorting them by activity, traffic volume, and application name, as well as quickly blocking connections with a single click. The developer emphasizes that the UI can be installed as a PWA, and the product is also aimed at monitoring the network activity of remote Linux servers.

Among the supported features of Little Snitch for Linux, the developer highlights:

  • viewing current and past network activity by applications;
  • displaying blocked connections, traffic history, and data transfer volumes;
  • scaling and filtering by time ranges on the traffic chart;
  • one-click connection blocking;
  • support for blocklist with automatic updates;
  • importing lists in the formats of 'one domain/host per line', /etc/hosts, and CIDR ranges;
  • creating custom rules for processes, ports, and protocols;
  • the possibility to enable authentication for access to the web interface;
  • replacing the eBPF component and web UI with custom builds.

At the same time, the project has a number of important limitations. Little Snitch for Linux operates on kernels Linux 6.12 and newer with BTF support; the developer also warns that hardened kernel configurations may be incompatible with the program. In addition, the product is explicitly described as a solution "for privacy, not security": due to eBPF limitations, under high load situations may occur when packets cannot be reliably matched with processes or DNS names.

The licensing model for the Linux version is mixed: the eBPF component and web UI are published under GPLv2, while the daemon and CLI tool remain proprietary., but are distributed for free and allow for unrestricted use and redistribution.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster