| ▲ | ProllyInfamous 3 hours ago | |||||||
Little Snitch is a user-friendly, software-level blocker, only – use with caution. Just FYI: LittleSnitch pre-resolves DNS entries BEFORE you click `Accept/Deny`, if you care & understand this potential security issue. Your upstream provider still knows whether you denied a query. Easily verifiable with a PiHole (&c). I liken the comparison to disk RAIDs: a RAID is not a true backup; LittleSnitch is not a true firewall. You need isolated hardware for true inbound/outbound protection. | ||||||||
| ▲ | gruez 3 hours ago | parent [-] | |||||||
>Just FYI: LittleSnitch pre-resolves DNS entries BEFORE you click `Accept/Deny`, if you care & understand this potential security issue. Your upstream provider still knows whether you denied a query. Easily verifiable with a PiHole (&c). This also feels like an exfil route? Are DNS queries (no tcp connect) logged/blocked? | ||||||||
| ||||||||