logoalt Hacker News

thewanderer1983today at 9:58 AM1 replyview on HN

Does little snitch and similar software work against solutions like Paqet?

https://github.com/hanselime/paqet


Replies

littlesnitchtoday at 12:14 PM

On macOS, it requires access to /dev/bpf. That's why we added filter rules for bpf there.

On Linux, we intercept at a level where packets already have an Ethernet header. I hope that Paqet injects before* this layer, but only a test can give the proof.