-
Notifications
You must be signed in to change notification settings - Fork 4
Security and Privacy
Full policy / politique complète : PRIVACY.md · Threat model / modèle de menace : docs/threat-model.md
-
Everything runs locally —
snitch.dband logs never leave the machine. No telemetry, no analytics, no crash reporting, no account. - The only possible outbound call is the opt-in DB-IP Lite download in Settings — it requires an explicit click and is the single consent-gated network request in the codebase.
-
Geolocation is offline-only — DB-IP Lite ships gzip'd in
backend/data/geo/and extracts on first run. MaxMindGeoLite2-*.mmdbfiles dropped into<data_dir>/geo/are also picked up. - LAN discovery is passive — the system ARP table, never a broadcast scan.
| Mechanism | Detail |
|---|---|
| API token | Per-launch random token, required on every REST endpoint and the WebSocket (X-Snitch-Token header or ?token=). Stored in data/api_token.txt. |
| Loopback default | The API binds 127.0.0.1 in every mode. SNITCH_BIND=0.0.0.0 only if you explicitly want LAN access — token auth still applies. |
| Origin allowlist | CORS + WebSocket origins restricted to localhost:5173, the backend's own origin, and Electron file:// pages. |
| No secrets in logs |
GET /diagnostics returns a runtime snapshot without secrets — safe to attach to bug reports. |
Live capture uses libpcap/BPF — it reads packets on your interfaces, which is why it needs elevated privileges (sudo on macOS/Linux, Npcap + admin on Windows). Snitch reads traffic; it does not modify, block or inject anything. SNITCH_DEMO=1 runs fully unprivileged.
Sliding window in local SQLite — 24 h by default, configurable via the retention_hours setting. Aggregates live in host_history / process_history; alert suppressions in alert_suppressions. Delete the data directory to wipe everything.
-
Tout tourne en local —
snitch.dbet les logs ne quittent jamais la machine. Pas de télémétrie, pas d'analytics, pas de rapport de crash, pas de compte. - Le seul appel sortant possible est le téléchargement opt-in de DB-IP Lite dans Réglages — clic explicite obligatoire, c'est la seule requête réseau du code.
-
Géolocalisation 100 % hors ligne — DB-IP Lite embarquée gzipée, extraite au premier lancement. Les
.mmdbMaxMind déposés dans<data_dir>/geo/sont aussi pris en charge. - Découverte LAN passive — table ARP système, jamais de scan broadcast.
| Mécanisme | Détail |
|---|---|
| Jeton API | Jeton aléatoire par lancement, exigé sur chaque endpoint REST et le WebSocket. Stocké dans data/api_token.txt. |
| Loopback par défaut | L'API écoute sur 127.0.0.1 dans tous les modes. SNITCH_BIND=0.0.0.0 uniquement pour un accès LAN explicite (jeton toujours exigé). |
| Allowlist d'origines | CORS + WebSocket restreints à localhost:5173, l'origine du backend et les pages file:// d'Electron. |
| Aucun secret dans les logs |
GET /diagnostics renvoie un instantané sans secrets — sûr à joindre aux rapports de bug. |
La capture utilise libpcap/BPF — lecture des paquets sur vos interfaces, d'où les privilèges élevés (sudo macOS/Linux, Npcap + admin Windows). Snitch lit le trafic ; il ne modifie, ne bloque ni n'injecte rien. SNITCH_DEMO=1 fonctionne sans privilège.
Fenêtre glissante en SQLite local — 24 h par défaut, configurable via retention_hours. Supprimez le dossier de données pour tout effacer.
Snitch Wiki
Getting started / Démarrage
Docs (EN + FR)
Help / Aide (EN + FR)
Project / Projet