HN Hall of Fame Weekly email

OpenSnitch is a GNU/Linux port of the Little Snitch application firewall

github.com Software & code Source code Security & privacy Class of 2022-06 Hall of Fame
Screenshot of github.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 4 calendar years, with breakout response in 4 of them.

submissions
8
submitters
8
observed span
2017–2024
peak thread · 131 comments
589 pts
latest 20+ return · 2024-08-10
408 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

Little Snitch is one of my favorite apps in the world, and it's one of the very first things I install on any new Mac. For those unfamiliar, it monitors and restricts outbound connections that your applications are trying to make. For example, you might be working away and suddenly get a popup saying: "Chrome is making an outbound TCP connection to adserver.trackallusers.com, port 9876. Do you want to: - Allow or Deny the connection... - To all hosts in…

I've tried to use it extensively (as an interactive firewall). However there are just some problems (that are not the fault of OpenSnitch) that I'm not even sure that are even solvable. For example, supposed I run `curl` on the terminal, I can either always decide on a case-by-case basis to allow it thru, or I'm required to whitelist it permanently. Once I've whitelisted generic tools like `curl` or `wget`, then the floodgates are really open, since any malware that…

I really hope this tool takes off! The problem with existing tools (iptables & co.) is that they are pretty much useless for "ordinary power users". I don't want to spend my precious time checking logs and trying to figure out if yeat another tool / extension / ... decided it needed to phone home (or worse). Ideal UI? Block everything, inform me about it (via unobtrusive non-modal message notification) and let me decide on a case-by-case basis what to…

annnnd·319-point thread·

I love Little Snitch. I hate Little Snitch. The first time I installed and ran Little Snitch, I was pretty much flabergassted at how chatty my system was. Just constantly being presented with requests to the point that made it impossible to work. I loved learning how prevelant E.T. phoned home. But then as I was just constantly inundated with those requests, I hated having to constantly deal with it. Now it's time to whitelist/authorize/etc. But do I really want…

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
4

100+ points or 50+ comments

Total points
1545

reference only — not used in Hall rules or ranking

Total comments
410

reference only — not used in Hall rules or ranking

Every submission