Developer & ITOriginal Reddit post

6-months with Little Snitch 6 — what I learned about how much my Mac talks to the internet

Full contextOriginal content · Reddit

I’d been hearing about Little Snitch for years at this point. Colleagues swore by it. A couple of friends in security said it was the one paid app on their Mac they’d never give up. This sub mentions it constantly. And I kept putting it off. The reason was honestly just the price. $59 for a one-time purchase, single device. I’ve bought plenty of paid Mac software before like Bartender, Things, Soulver, the usual, but $59 for one machine felt like a lot for something I wasn’t sure I’d actually use. The free options (Lulu, the built-in firewall) seemed “good enough” on paper. Six months ago I finally decided to check. Writing about it here in case anyone else has been on the fence for the same reason. Why I finally bought it A couple of things tipped me over: I’d read one too many threads about how chatty modern apps are with telemetry and analytics, and I realized I genuinely had no idea what was leaving my machine. I tried Lulu first for about a week. It blocks fine, but it doesn’t show you anything. I wanted visibility, not just a deny list. The 30-day demo mode (it cycles on and off in 3-hour windows) was enough to convince me the alert UX was actually decent, not the clunky popup hell I’d half-expected. So I bought it. First night, Adobe Creative Cloud alone tried to phone home to something like 22 different domains in the first 20 minutes. I hadn’t even opened Photoshop. That was the moment I realized why everyone had been telling me to buy this thing. The first week is rough Not gonna sugarcoat it. The first few days were a mess of popups. Every app I opened wanted to talk to five different servers and I had no idea which ones were legit. Spotify needs to reach its CDN, fine. But why is iStat Menus connecting to an analytics domain in Ireland? Why is my PDF reader checking for updates and sending telemetry and loading fonts from a third-party host? I almost uninstalled it twice. The cognitive load of “is this connection real or sketchy” on top of actually trying to work was rough. What saved me: - I stopped trying to make perfect decisions. If something looked legitimate (CDN, official domain, obvious update server), I allowed it for that app only and moved on. - I leaned on the Research Assistant feature pretty heavily. It tells you what a domain is for and whether it’s known sketchy. - I turned on Silent Mode (deny mode) for a couple of evenings while I just watched the Network Monitor and learned what normal looked like. By end of week 2 the popup volume had dropped maybe 80%. By week 4 I was getting maybe 2-3 alerts a day, almost always for something new. What I actually use it for now (months 2–6) Honestly, the popups aren’t even the main value anymore. The Network Monitor is. Being able to open it and see, in real time, every process on my machine and what it’s connecting to — that’s the thing I didn’t know I wanted. Some specific things I caught or learned: - A small menu bar utility I’d been using for over a year was reaching out to an analytics endpoint every 15 minutes. Not malicious, just noisy. Blocked it, app still works fine. - Adobe is genuinely something else. Even with Creative Cloud signed out, there are background processes that try to reconnect constantly. My deny rules for Adobe alone are probably 30+ entries. - One of my browsers was making connections I couldn’t explain even with all extensions disabled. Turned out to be a built-in feature I’d never noticed in settings. - Random one: a game I hadn’t opened in 4 months was still checking in daily with its publisher’s telemetry server. The traffic map and the live connection graph are honestly more useful for vibes than for action. But the DNS encryption and the blocklist subscriptions (I’m running Steven Black’s hosts list through it) are doing real work. According to my stats panel I’m at something like 27,000 blocked connections over 6 months. No idea how meaningful that number actually is, but it’s not zero. The honest pros and cons What’s good: - The Network Monitor is genuinely best-in-class. Nothing else on macOS gives you this view. - Rule management scales reasonably well even with ~800 rules. Search and filtering work. - It’s stable. In 6 months I’ve had 2 crashes. Performance hit is invisible to me. - The DNS encryption + blocklist combo means it’s also doing some of what a Pi-hole would, without the Pi. - Native feel. It looks and behaves like a Mac app, not an Electron port of a Windows tool. What’s not: - The price still stings a little. $59 single-device is on the high end for one-time Mac software, especially if you have multiple machines. The family/multi-device pricing helps but it’s still not cheap. - The learning curve is real. If you don’t enjoy thinking about networking even a little, you’ll bounce off it. - Rule sprawl is a thing. After 6 months my rule list is genuinely hard to audit. I’ve started over once. - Alerts during screen sharing or presentations are awkward. Silent Mode helps but you have to remember to flip it. - Occasional false positives where I block something and an app starts misbehaving in non-obvious ways. Tracking that down took me a couple of hours more than once. Edge cases worth flagging A few things that took me a while to figure out: - Battery impact: basically nothing I can measure. Older Intel Macs apparently see more of a hit from what I’ve read. Major macOS updates can break things briefly. The Sequoia 15.1 update needed a reinstall of the kernel-level component for me. Took 5 minutes but caught me off guard. - iCloud-related connections are a rabbit hole. Block the wrong one and Calendar sync silently fails for a day before you notice. - VPN interactions: Mullvad needed some specific allow rules before it would route correctly. What about Lulu / Radio Silence / built-in firewall? Like I said, I tried Lulu for about a week before paying for Little Snitch. It’s free, it’s open source, the developer is great. For pure outbound blocking it works. What it doesn’t have is the Network Monitor depth, the traffic map, the connection history, or the same rule management. If you mainly want a “block this thing forever” tool and don’t care about visibility, Lulu is genuinely fine and you should try it first — you might not need to spend the $59. Radio Silence is even simpler — it’s basically a deny list. Cheaper, easier, way less powerful. The built-in macOS firewall doesn’t do outbound at all. It’s not in the same category. So for me, Little Snitch earned the price by being the only one with the monitoring layer. If I just wanted blocking, I’d be on Lulu and $59 richer. Was the price worth it Six months in, yeah. I’d buy it again. The thing that finally justified the cost in my head wasn’t any single feature — it was that I now actually understand what’s running on my machine. That’s not a thing I can get from a free tool. That said, I want to be fair: if you’re someone who’s going to install it, click “allow” on everything, and never open the Network Monitor, don’t pay for this. You’re paying for visibility and control, and visibility only matters if you’re going to look. Lulu plus a decent blocklist is a better deal for that crowd. Not affiliated with Objective Development. Paid full price. No referral.

01Demand tags
Developer & ITPricing or licensingDesktop appNot applicable

Collected discussion

25 collected

25collected144reported on Reddit
u/itsdanielsultan

Here is the TLDR, since it was quite long: After six months with Little Snitch 6 , someone on r/macapps finally wrote up why the $59 was worth it. The first week is brutal with popups, but once you push through, the real value kicks in: the Network Monitor shows you every single connection your Mac makes in real time. They caught Adobe quietly hitting 22 domains without Photoshop even open, a forgotten game phoning home daily, and a tiny menu bar app pinging analytics every 15 minutes. The free alternatives like Lulu handle blocking fine, but they don’t show you anything. Little Snitch does. If you care enough to look, it’s worth the price. If not, save the money.

u/aykay55Reply

To add on to this, you can achieve some of the same things with a DNS level intermediary like NextDNS that will log all URLs requested across your devices and offers the ability to add blocklists to prevent tracking and unsafe websites, and is very customizable. And it’s free, if you do a normal amount of web browsing. NextDNS opened my eyes to how many sites will contact Google and Facebook. I forgot that opening emails often “phones home” and I can see it clearly when I open an email from my bank without opening any of my banking apps or websites in the same time frame.

u/Downtown-Art2865OPReply

the bank email thing is wild once you see it. yeah NextDNS + Little Snitch is honestly the proper combo. DNS catches the browser traffic, LS catches the app-level stuff.

u/PaulMuadDib-UsulReply

I had LittleSnitch on my old Mac and the network Monitor is really cool! I tried to block mostly all suspicious Google or FB connections. But after a while I just gave up and did not use it much anymore. The main reason why I stopped actively using it (and also did not install it on my new Mac yet), is that when certain things occasionally did not work as expected, I could never be sure, whether this was a problem with the respective software or my hand-made blocklist settings. In other word, chances are there that you break things with that tool. Same with LuLu. I have this installed, because I somehow like the aspect of having control over what apps are calling home, but in the end I just allow every connection, to make sure that all apps work as expected and that they catch the latest updates - now that MacUpdater has been abandoned.

u/FirmSupermarket6933

From Little Snitch FAQ: Can I use my single license on a second computer? A single license is valid for all your machines as long as you are the only user. Looks like you don't have to buy new license for each machine.

u/ChainsawJaguar

I love Little Snitch. It's one of the first things I install on a new Mac. I've been a paying customer since 2017.

u/Downtown-Art2865OPReply

2017 is real loyalty. six months in for me and I can already tell it’ll be a day-one install on the next Mac.

u/MaxGaav

If you are in the same boat, recently Sniffnet was presented here. A free app to monitor Internet traffic.

u/Downtown-Art2865OPReply

oh nice, hadn’t seen Sniffnet before. looks like it’s monitoring-only though, no blocking? might actually pair well with Lulu for the people who want visibility but don’t want to pay. adding it to the list to try.

u/amerpie

My Mac Contacted 63 Different Apple Owned Domains in One Hour - While Not in Use | AppAddict

u/Downtown-Art2865OPReply

63 in an idle hour is basically one every minute that’s more than telemetry. Apple is the one vendor most LS users blanket-allow because the alternative breaks iCloud, the App Store, and half of macOS, which means almost nobody actually audits what’s in there. saving the post for tonight. thanks for resurfacing 🫡

u/areyouredditenough

VPN interactions: Mullvad needed some specific allow rules before it would route correctly. Great write-up. Same, I've been usng LS since v4 I believe and also use MullVap. Curious, which rules you added? Care to share? I sometime have issues with DNS encryption working with MV, other I don’t. Strange.

u/Downtown-Art2865OPReply

the Mullvad rules are mostly the obvious ones like allow the mullvad-daemon process, allow the VPN app itself, allow the WireGuard traffic, and a few API endpoints (api.mullvad.net and friends) so it can pull server lists and auth. nothing exotic. the only one that took me a minute to figure out was DNS, depending on how you’ve got LS’s DNS encryption set up, you sometimes need an explicit allow for Mullvad’s DNS servers or it gets weird. which actually connects to your other question — the intermittent DNS encryption issue is almost certainly a race condition between the VPN tunnel coming up and LS’s encrypted DNS trying to resolve through it. when the tunnel isn’t fully up first, you get inconsistent behavior. a lot of people just disable LS’s DNS encryption when on MV since Mullvad does its own DNS anyway. the redundancy isn’t really helping you. are you running it always-on or toggling? curious if the inconsistency tracks with how you connect.

u/cristi_baluta

I think all the devs in this sub are rolling in their chair when you block the analytics and crashlogs. The tool could be useful for the scripts that steal your data we keep hearing in the macos sub, but it looks like you spend more time babysitting your network than using the apps

u/Downtown-Art2865OPReply

fair, the first month genuinely is babysitting. after that it’s pretty quiet unless I install something new. and yeah, dev guilt is real. I’m one too, I know what’s in those crashlogs

u/nolookertuta

LS Devs, OP just sold an entire bunch of us on your app - put up a discount now and we (I) will buy it!

u/Thick_Replacement876

One thing that didn’t sit well with me is that it installs system-level network components that can be annoying to remove cleanly. So if you’re not sure you need it, I wouldn’t install it just to try it out. And if you do know you need it, you probably already have some form of router-level blocking or network monitoring set up anyway. Just my 2c, but if you mostly use your computer at home, don’t travel with it much, and rarely connect to public Wi-Fi, something like this is probably overkill for your needs.

u/broad101

worth using over something like Lulu? I have been running with this since having a Mac and never had any issues ?

u/Calmhat3392

Thank you for sharing your detailed experience with Little Snitch and for the insightful comparisons with other application firewalls! I noticed the first point in your “What’s not” list regarding the Little Snitch Single License that needs to be clarified to ensure accuracy. The definition is actually as follows: The Single license permits either a single user to use the software on multiple computers or multiple users to use the software on a single computer. However, it does not allow multiple users to ever use the software on multiple computers, regardless of whether such use is concurrent.

u/zenassati

The most important app ever !!! The first thing i install on a new mac !