Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is it open source? Couldn't find anything on their site which is disappointing.


I realize that not everything can be made open source, but I personally don't trust closed source security applications.


What's to trust exactly?

It blocks connections to domains/IPs you want it to, and allows others.

You can easily verify that it behaves correctly with common network tools.

This is not some deep cryptography shit...


What if it doesn't show a specific application making requests? What if it chooses to not do that? How do we know?


As I said, "You can easily verify that it behaves correctly with common network tools".

Track its behavior from an exit node of your network and see whether it matches your rules.

Not really much difference than manually checking some tens of thousands of lines of an open source application, or trusting that the binary you got from the repo corresponds to the source (and of course even hashes can be tampered).

Plus, even if it chose "to not show a specific application making requests" you'd still be blocking all others apps, and thus way better off than not having it installed.


I don't trust that it's not doing data collection of it's own.


Funnily enough, I vaguely recall that the crack for an older version involved setting a rule where the app would block its own traffic to their own license server. I'm not sure that validating a license counts as data collection, but still pretty funny IMO.


The app costs $35. I presume this is a workable business for the developer, and therefore little economic incentive for data collection or other backdoor/nefarious tactics.

I'm much less trusting of free software like most ad-blockers where I have to wonder how they're really making their money.


It depends what you mean by "free". Of course all software should be handled with varying degrees of skepticism, but open source software can be directly verified (though this also requires building from source), and you don't have to just hope that the author was honest.


They've also been on the Mac for 10+ years.


Objective Development were there from the very beginning of Mac OS X.

And prior to that, they were a well known developer for NeXT. Their LaunchBar app originated on NeXTSTEP.


exactly. how can one be sure that it doesn't use the network for its own nefarious purposes while hiding its own network activity ?


By checking the traffic leaving your network from another machine? DUH!


Watch network traffic from a box with LS installed.


No, it's a commercial app (and an age old OS X staple, been using it for over a decade).


It's not.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: