Skip to content

FreeSnitch 0.4.0

Choose a tag to compare

@isaaclins isaaclins released this 14 Aug 07:44
· 70 commits to main since this release

FreeSnitch 0.4.0

The release where FreeSnitch stops only answering "is this allowed?" and starts answering "what is my Mac actually talking to, and has that changed?"

Insights, a traffic memory

A new screen (Command-Option-I) that groups traffic by app, showing what each one contacted, how often, and when it was first seen.

  • Names come only from DNS answers this Mac actually saw. There are no online lookups, and the build now fails if that ever changes.
  • Nothing is enforced automatically. Insights can propose a rule, but a proposal becomes a rule only when you accept it.
  • Addresses that were never resolved to a name get their own section, described as a signal rather than a verdict.
  • Storage is root-owned, with 14 days of raw records and a year of rollups, an off switch, and a purge that really removes the database.

Alert mode you can leave switched on

Alert mode now interrupts on first contact only. A destination this app has talked to before is allowed without a prompt, so the constant re-asking is gone, while explicit rules still decide first.

If the contact history is unavailable, stale, or unreadable, FreeSnitch asks rather than assuming. The alert also tells you why it is asking, and shows a running tally of how many contacts were allowed silently.

Apps that change behaviour after an update

FreeSnitch records the version of each app alongside what it contacted, and flags destinations that only appeared after an update, showing the old and new build. It states co-occurrence, not causation, and never blocks anything on its own.

Profiles: a place plus how strict you are there

Profiles are real now. Exactly two layers ever apply: your Always rules plus the selected profile. Deny layers stack.

  • A place is recognized by the network's gateway hardware address, not the Wi-Fi name, because reading the Wi-Fi name requires Location Services and a firewall should not demand that.
  • Automatic switching only happens for a network you bound yourself. An unknown network never switches your profile.
  • A switch is always visible in the menu bar, names what was paused, and is undoable.
  • Switching does not tear down connections you already have open; the new strictness applies to new ones.

IP and CIDR blocklists

Address feeds are now their own kind of list, enforced in the packet filter where addresses are actually seen, so a connection made straight to an IP is covered.

Safety is decided before the feed is consulted: loopback, FreeSnitch's own traffic, DHCP, and your configured resolvers can never be blocked by a feed, and your own rules still win. A feed that fails to download, is too large, or is malformed contributes nothing and says why. If the packet filter rejects an anchor carrying a feed, the anchor is reloaded without it, so a bad feed can never cost you your own rules.

Measured: 120,000 entries load in about a second, and lookup cost stays flat as the list grows.

Answer alerts from the command line

freesnitch alerts list
freesnitch alerts answer <ID> --deny --scope ip --temporary

Alerts are listed with a stable ID, the process, the destination, and the seconds left. Answering is exactly-once: a second answer, an expired alert, or an unknown ID each report specifically what happened instead of failing vaguely.

The FreeSnitch app must be running, because a connection alert is a flow paused against the running app. The CLI says so plainly instead of looking broken, and a flow never stays paused longer than its existing timeout.

Uninstall from inside the app

Settings now has an Uninstall screen that removes FreeSnitch properly instead of leaving a privileged helper and a network extension behind. It explains what macOS will not let it remove without your involvement rather than pretending it succeeded.

One window, with pages

FreeSnitch used to open a separate window for every view. Monitor, Rules, Insights, Profiles and Settings are now pages in a single window with a sidebar, so opening Rules switches the window you already have instead of adding another one to your Dock and Mission Control. It remembers both the window and the page you were on.

The connection alert is deliberately still its own panel, because it has to appear over whatever app you are in.

The map shows who you are actually talking to

  • Connection arcs from your Mac to every endpoint, drawn as curved great-circle paths and split correctly at the antimeridian. Weight and opacity follow how busy the endpoint is.
  • No Location Services. The arcs used to be hidden entirely unless you granted location access, which is an absurd thing for a firewall to ask. Your Mac is anchored by a pin you can place yourself, with an offline time-zone estimate until you do, labelled as an estimate. CoreLocation is now strictly opt-in and off by default.
  • City-level nodes that split as you zoom. Every IP in a country used to land on the same dot. The map now groups by country when zoomed out and separates into real cities as you zoom in.
  • IPv6 endpoints appear at all. They were never geolocated before, so a meaningful share of traffic was silently missing from the map.

Geolocation stays offline. The database is downloaded once and compiled into a memory-mapped index; there are no per-connection lookups. IP geolocation by DB-IP, CC BY 4.0.

The monitor groups by app

The live monitor is a tree: each app expands into the destinations it actually contacted, with rolled-up totals and traffic bars, and allow or deny controls on every row so you can decide where you are looking. Rows are ordered by arrival and never re-sort by traffic, so a row cannot move out from under your cursor between aiming and clicking.

Keyboard

Pages follow the sidebar: ⌘1 Network Monitor, ⌘2 Rules, ⌘3 Insights, ⌘4 Profiles, ⌘5 Settings, and ⌘, still opens Settings. The old shortcuts encoded the page's name rather than its position, ⌘⌥N read as "new", and Profiles had no shortcut at all.

Fixes

  • DNS answers were being pruned at their five-minute TTL, which would have erased nearly every hostname and made almost all traffic look unresolved. They now age out with the 14-day window.
  • Rules already covered by an existing enabled rule are no longer re-proposed.
  • A fresh install now starts in Silent Allow and says so, instead of quietly implying it is blocking.
  • Remembering an alert for a destination with no host name produced a rule with no destination constraint at all, so an allow silently granted that app access to everything and a deny blocked it from everything. The destination is now carried into the rule, and a decision that cannot be expressed is refused rather than stored.
  • The main window rendered blank panes: the sidebar and the app tree drew nothing and the remaining panes showed only their lower half.
  • Top Processes listed bundle identifiers at 0 B while the rest of the same screen showed correct totals.
  • The map legend was drawn on top of the Apple Maps wordmark.
  • ⌘, cleared the page name from the window's title bar.