Originally posted on r/macapps.
I’d been hearing about Little Snitch for years at this point. Colleagues swore by it. A couple of friends in security said it was the one paid app on their Mac they’d never give up. This sub mentions it constantly. And I kept putting it off.
The reason was honestly just the price. $59 for a one-time purchase, single device. I’ve bought plenty of paid Mac software before like Bartender, Things, Soulver, the usual, but $59 for one machine felt like a lot for something I wasn’t sure I’d actually use. The free options like Lulu and the built-in firewall seemed "good enough" on paper.
Six months ago I finally decided to check. Writing about it here in case anyone else has been on the fence for the same reason.
A couple of things tipped me over:
So I bought it.
First night, Adobe Creative Cloud alone tried to phone home to something like 22 different domains in the first 20 minutes. I hadn’t even opened Photoshop. That was the moment I realized why everyone had been telling me to buy this thing.
Not going to sugarcoat it. The first few days were a mess of popups. Every app I opened wanted to talk to five different servers and I had no idea which ones were legit. Spotify needs to reach its CDN, fine. But why is iStat Menus connecting to an analytics domain in Ireland? Why is my PDF reader checking for updates and sending telemetry and loading fonts from a third-party host?
I almost uninstalled it twice. The cognitive load of "is this connection real or sketchy" on top of actually trying to work was rough.
What saved me:
By the end of week 2 the popup volume had dropped maybe 80%. By week 4 I was getting maybe 2-3 alerts a day, almost always for something new.
Honestly, the popups aren’t even the main value anymore. The Network Monitor is. Being able to open it and see, in real time, every process on my machine and what it’s connecting to is the thing I didn’t know I wanted.
Some specific things I caught or learned:
The traffic map and the live connection graph are honestly more useful for vibes than for action. But the DNS encryption and the blocklist subscriptions, I’m running Steven Black’s hosts list through it, are doing real work. According to my stats panel I’m at something like 27,000 blocked connections over 6 months. No idea how meaningful that number actually is, but it’s not zero.
A few things that took me a while to figure out:
Like I said, I tried Lulu for about a week before paying for Little Snitch. It’s free, it’s open source, and the developer is great. For pure outbound blocking it works. What it doesn’t have is the Network Monitor depth, the traffic map, the connection history, or the same rule management. If you mainly want a "block this thing forever" tool and don’t care about visibility, Lulu is genuinely fine and you should try it first. You might not need to spend the $59.
Radio Silence is even simpler. It’s basically a deny list. Cheaper, easier, way less powerful.
The built-in macOS firewall doesn’t do outbound at all. It’s not in the same category.
So for me, Little Snitch earned the price by being the only one with the monitoring layer. If I just wanted blocking, I’d be on Lulu and $59 richer.
Six months in, yes. I’d buy it again. The thing that finally justified the cost in my head wasn’t any single feature. It was that I now actually understand what’s running on my machine. That’s not a thing I can get from a free tool.
That said, I want to be fair: if you’re someone who’s going to install it, click "allow" on everything, and never open the Network Monitor, don’t pay for this. You’re paying for visibility and control, and visibility only matters if you’re going to look. Lulu plus a decent blocklist is a better deal for that crowd.
Not affiliated with Objective Development. Paid full price. No referral.