Skip to content

FreeSnitch 1.0.0

Latest

Choose a tag to compare

@isaaclins isaaclins released this 15 Aug 11:50
· 7 commits to main since this release

FreeSnitch is a free, open-source application firewall for macOS. It shows which app on your Mac talks to which server, puts it on a live map, and lets you allow or deny it per process. MIT licensed, no account, no telemetry.

Download

File What it is
FreeSnitch-1.0.0.dmg Disk image. Start here.
FreeSnitch-1.0.0.zip The same app as a zip.
FreeSnitch33-*.delta Sparkle delta updates. The app's updater uses these; you never need them by hand.
  • Requires macOS 13 or later. One universal build for Apple Silicon and Intel.
  • Signed with a Developer ID, notarized and stapled by Apple. This is the firewall build, with the Network System Extension.
  • Updates arrive through the built-in Sparkle updater.

Install

  1. Open the disk image and drag FreeSnitch to Applications. It has to run from there, or macOS will not install its helper.
  2. Open it and allow the helper in System Settings > General > Login Items & Extensions > Allow in the Background.
  3. When macOS asks, allow the FreeSnitch system extension. That is the part that filters per process.

Coming from PureSnitch? Run Scripts/uninstall_puresnitch.sh first; the two content filters must not run together.

Checksums (SHA-256)

610ef02c2201dba159172f774fd22fa88f6cbc3b79449bef9dacaab5ce361044  FreeSnitch-1.0.0.dmg
d52a450147643451b8a54d7489aeeb0350a2f26105d9ab15ca2c10bff205c08a  FreeSnitch-1.0.0.zip

Also attached as SHA256SUMS.txt. Check with shasum -a 256 -c SHA256SUMS.txt in the folder you downloaded to.


What's new in 1.0

FreeSnitch 1.0 is the release where the app stops looking like a firewall console and starts looking like a Mac app. The filtering engine, the helper and the network extension are the ones you have been running since 0.4.5. What changed is every screen in front of them, and the twenty issues that said those screens were hiding, mislabelling or quietly losing what they were supposed to tell you.

The whole app is native now (#68)

Settings used to be the only page built from system controls, so it was the only page that inherited Mac behaviour: correct control sizing, focus rings, keyboard traversal, accessibility, contrast. Every other page was hand-drawn on a fixed dark palette.

  • Rules is a real Table with sortable columns, selection, and a selection-aware context menu.
  • Insights and the Network Monitor are real Lists, with system selection and arrow key traversal.
  • The window has a real NSToolbar, a real sidebar material, and one translucent band instead of a staircase of them.
  • The connection alert is a macOS permission dialog rather than a drawing of one.
  • The app's own colour palette is gone. Surfaces are system backgrounds and materials, text is semantic label colours, and emphasis follows the accent colour you picked in System Settings. Light mode, Increase Contrast and the text size setting work without a per-colour audit. What survives is two named colours, sent and received, because in versus out is the one distinction the app makes with colour and it must not move when your accent does.

Rules

  • The table says which rules are in force (#134). There is an "Applies to" column, drawn in secondary when that profile is not active, and a Profiles section in the sidebar that filters to Always or to one profile. A rule waiting for a place you are not in no longer reads exactly like one enforcing right now.
  • The rule editor offers every profile (#134). It used to offer Always or the active profile and nothing else, so a rule for a third profile could be neither created nor moved. A row's context menu can move an existing rule between profiles.
  • Rule groups are real (#134). The four group rows were hardcoded names nothing ever wrote, so all four were permanently empty while the group rules actually carry, Insights, had no row. The section is built from the rules and is left out when there are none.
  • The inspector says when (#134). Created, last used, and, for a temporary rule, when it expires.
  • The Information pane is resizable and remembers its width, and so is the sidebar (#123). The window minimum came down to 900 by 560, which fits the smallest display Apple ships.

Blocklists

  • One checkbox, one meaning, one source of truth (#135). The checkbox in the Rules sidebar meant "enabled globally" and the identical-looking one under Profiles meant "belongs to this profile", and they read from two snapshots that could disagree on screen. Both now mean the profile-scoped thing the helper actually enforces, from one snapshot.
  • Refreshing says what it is doing (#135). Downloading hundreds of thousands of entries used to be silent. There is a spinner while it runs and a sentence afterwards saying how many lists and names arrived, or what went wrong.
  • Adding a list waits for the answer (#135). The editor used to dismiss before the helper replied and put the failure on a page you were not looking at. It stays up until the helper answers and shows the refusal in place.
  • A new list says "Not downloaded yet" instead of a bare 0, and the header and footer counts agree while you are searching (#135).
  • You can search a blocklist, edit any of them, and see what is on one.

Network Monitor and the map

  • The denied badge lands on the denied list (#138). "Recently denied" in the menu bar panel used to open a Monitor that never showed whether a connection was allowed, denied or pending. It opens a filtered view now.
  • The map is legible and follows the appearance (#121). Labels were white text on fixed black at hardcoded sizes, down to 8 points. They use text styles and materials now, so they respond to the appearance, Increase Contrast and the text size setting.
  • A place on the map answers questions (#138). Nodes carry the apps that reached them, and a Locations menu opens a card naming those apps with the connection count and traffic. Each place also says its own name exactly once, which it previously did twice.
  • Location Services is a Settings row (#138), with the standard explanation, instead of a privacy decision buried in an unlabelled glyph floating on the map. It is off by default and the map estimates from your time zone.

Insights, profiles and the menu bar

  • Insights reads like a report rather than a console, its actions actually run, and rules it proposes carry their group.
  • Profiles can be told apart at a glance, the profile chip picks a profile, and Profiles is a list with a detail pane.
  • The menu bar panel is 320 points wide, the width it always declared and never got.

Uninstall

The uninstall says what it does, keeps its place, and quits (#133). The plan now lists the steps in the order they happen, including the one place FreeSnitch unregisters its own privileged service, which only ever happens in an uninstall you confirmed. It runs in its own sheet, so switching pages halfway through cannot tear it down, and it can be resumed if you close it between the deactivation and the removal. When it finishes it offers to quit, and quitting takes the menu bar icon with it.

Also fixed

Destructive actions ask first, and they all ask the same way. Failures say what went wrong in the words you read, not in the words the code throws. Disabled controls mean disabled. The alert panel is as tall as its card. The Spaces switch decides where alerts appear. Values in the Information pane really do copy. The keyboard drives the lists.

Known limits

Blocklists filter DNS names only. They do not stop connections made to hardcoded IP addresses or to names resolved by an app's own encrypted DNS, such as Chrome and Firefox with DoH enabled.

Map locations are estimates from IP geolocation, not measurements.