bk99.de entertain the web since 1997

Little Snitch for Linux: making connections visible

Summary

Objective Development shows an eBPF-based network monitor that maps Linux connections to applications and makes them controllable. Little Snitch requires Linux 6.12 or newer and BTF support. The interface runs locally on port 3031 and can be installed as a PWA.

Ideas

  • The connection view combines processes, destinations, data volumes and history over time.
  • Selecting a time range in the chart filters the visible connections at the same time.
  • Blocklists block domains, hosts and CIDR networks from several common formats.
  • Custom rules combine processes, ports and protocols.
  • eBPF provides process context without deep intervention in applications.
  • Heavy traffic can overflow mapping caches and make results incomplete.

Insights

  • Visibility and access control complement each other but do not replace system hardening.
  • Network mapping remains probabilistic when DNS, caches and processes drift apart in time.
  • Good privacy tools state their technical limits explicitly.

Facts

  • The vendor explicitly positions the product for privacy, not security.
  • The interface and eBPF components are licensed under GPLv2; the daemon remains proprietary.

Recommendations

  • Use the tool for observation, not as the sole security barrier.
  • Check blocking rules after updates against the services you need and false positives.
  • Watch for cache losses especially on gateways and heavily loaded hosts.

References

Read the original article

Search the Web Archive