The Linux version of the Little Snitch application firewall has been released

The first release of the Linux version of the popular application firewall Little Snitch has been introduced, favored by macOS users. Little Snitch provides a graphical interface that allows for interactive monitoring of application network activity and blocking unwanted network traffic. The eBPF subsystem is employed for inspecting and blocking traffic in Linux. The eBPF programs, function library, and web interface are distributed under the GPLv2 license. The background process is written in Rust and is distributed under a proprietary license that permits free use and distribution.

The program allows users to visually assess which hosts applications in the system are currently trying to reach out, view the history of network activity, and track the volume of traffic. Users can block unwanted connections and connect to both personal and external blocklists, such as oisd.nl, intended for blocking ads, tracking services, telemetry collection systems, phishing, and other unwanted activities. External lists can be automatically updated. Blocking occurs at the level of IP addresses, subnets, and domain names. A whitelist of applications can be created to allow network activity.

The program includes a BPF handler that is loaded into the Linux kernel and a background process called littlesnitch. Management is done through a web interface accessible by opening the page "http://localhost:3031/" in a browser. It is possible to use the web interface as a standalone web application (PWA — Progressive Web App). It supports operation on systems with Linux kernel 6.12 and newer. The Linux version of the Little Snitch application firewall has been released The Linux version of the Little Snitch application firewall has been released

Additionally, it is worth noting that there is an open-source alternative to Little Snitch for Linux — OpenSnitch, which allows for interactive monitoring of application network activity. When applications attempt to establish network connections that do not fall under previously set permissions, OpenSnitch presents a dialog to the user, offering the choice to proceed with the network operation or block it. Christian Starkjohann, the developer of the Linux version of Little Snitch, mentioned that OpenSnitch did not meet his needs for monitoring network connections established by processes and blocking them with a single click.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster