-
Notifications
You must be signed in to change notification settings - Fork 4
FAQ
Is Snitch a firewall like Little Snitch? No — Little Snitch blocks connections; Snitch visualizes and explains them. They're complementary. Snitch is also free, open-source (AGPL-3.0), cross-platform and makes zero outbound calls.
Does it need root/admin?
Live capture: yes — that's how libpcap/BPF works (same as Wireshark). On Linux you can grant cap_net_raw to avoid running as root permanently. Demo mode (SNITCH_DEMO=1) needs no privileges at all.
Does any data leave my machine?
No. SQLite + logs stay local; the API binds 127.0.0.1 behind a per-launch token. The single possible outbound request is the opt-in DB-IP Lite download in Settings — and even geolocation works offline without it.
How accurate is process attribution?
Best-effort: Snitch snapshots OS connections via psutil and maps (proto, local_port) → (pid, name) — top 5 per connection. It can't attribute short-lived sockets that closed between snapshots.
Why is the macOS build unsigned? No Apple Developer certificate in the project budget. Right-click → Open works fine, and the whole pipeline is reproducible from source if you prefer building it yourself.
Windows/Linux native installers?
Linux: use Docker (sudo docker compose up --build). Windows: build from source (Npcap required). Native installers are on the Roadmap.
What languages does the UI support?
English and French — full interface, alerts and settings, one-click EN / FR toggle.
Does it slow down my machine? The pipeline is deliberately low-overhead: one bounded queue, one drain task at ~4 Hz, batched WebSocket updates every 250 ms. No per-packet coroutines.
Can I extend the tracker lists?
Yes — backend/classifier/lists/ holds plain-text domain lists. Add domains, restart the backend.
Why not just use Wireshark? Wireshark dissects raw packets for experts. Snitch gives the live, high-level "who talks to whom" picture anyone can read — graph, map, per-app, alerts.
Snitch est-il un pare-feu comme Little Snitch ? Non — Little Snitch bloque les connexions ; Snitch les visualise et les explique. Les deux sont complémentaires. Snitch est en plus gratuit, open-source (AGPL-3.0), multiplateforme et n'émet aucun appel sortant.
Faut-il les droits root/admin ?
Pour la capture réelle : oui — c'est le fonctionnement de libpcap/BPF (comme Wireshark). Sous Linux, cap_net_raw permet d'éviter le root permanent. Le mode démo (SNITCH_DEMO=1) n'exige aucun privilège.
Des données quittent-elles ma machine ?
Non. SQLite + logs restent locaux ; l'API écoute sur 127.0.0.1 derrière un jeton par lancement. Le seul appel sortant possible est le téléchargement opt-in de DB-IP Lite dans Réglages — et la géolocalisation fonctionne déjà hors ligne sans lui.
L'attribution par processus est-elle fiable ?
Best-effort : Snitch prend des instantanés psutil et associe (proto, port_local) → (pid, nom) — top 5 par connexion. Les sockets éphémères fermées entre deux instantanés ne peuvent pas être attribuées.
Pourquoi la build macOS n'est-elle pas signée ? Pas de certificat Apple Developer dans le budget du projet. Clic droit → Ouvrir fonctionne, et toute la chaîne est reproductible depuis les sources si vous préférez la compiler vous-même.
Des installateurs natifs Windows/Linux ?
Linux : utilisez Docker (sudo docker compose up --build). Windows : compilation depuis les sources (Npcap requis). Les installateurs natifs sont sur la feuille de route.
Quelles langues pour l'interface ?
Français et anglais — interface complète, alertes et réglages, bascule EN / FR en un clic.
Peut-on étendre les listes de trackers ?
Oui — backend/classifier/lists/ contient des listes de domaines en texte brut. Ajoutez vos domaines, redémarrez le backend.
Pourquoi pas simplement Wireshark ? Wireshark dissèque des paquets bruts pour experts. Snitch donne la vue d'ensemble en direct « qui parle à qui » lisible par tous — graphe, carte, vue par app, alertes.
Snitch Wiki
Getting started / Démarrage
Docs (EN + FR)
Help / Aide (EN + FR)
Project / Projet