Elektrine lite

← Feed

@TheIPW@lemmy.ml

Why I’m skipping the proprietary "Little Snitch" for Linux

2026-04-09 10:59 UTC

I saw the news about Little Snitch coming to Linux via eBPF and Rust. On paper, it looks fancy. In reality, the backend is closed source. Personally, I don’t see the point in installing a proprietary black box to monitor other black boxes. I’m sticking with my AdGuard Home setup and OpenSnitch for when I actually need to trace a binary. I wrote up my thoughts on why I think this is a solved problem for most FOSS-first home labs.

Replies (5)

  • @Obin@feddit.org 2026-04-09 11:15

    Also, you only need that stuff in the first place if you don’t have control over the operating system and your browser (like on Apple or Microsoft). For me, using a Firefox-based browser with uBlock Origin on both phone and desktop is enough so I don’t have to ever see ads, and I just don’t install spyware in the first place.

    Open ##1024764

  • @Brummbaer@pawb.social 2026-04-09 11:20

    Nice, something running in an eBPF context with a blob in the middle, what could go wrong ... Also there are already a lot of binary blobs in the kernel, that also makes me nervous a bit.

    Open ##2140054

  • @trackball_fetish@lemmy.wtf 2026-04-09 20:21

    Opensnitch +1

    Open ##2140055

  • @relic4322@lemmy.ml 2026-04-09 17:40

    Not familiar with this, but jumping on the opensnitch bandwagon. I use it, plus ufw, plus pihole. Kill the DNS lookups, kill it at the network level of possible, and if it's sneaky OpenSnitch catches it at the application layer.

    Open ##2140057

  • @corsicanguppy@lemmy.ca 2026-04-09 17:53

    Butbutbut the name has 'open' in it. How can this be? (I worked on OpenUnix and OpenLinux, so I get it)

    Open ##2140058