Wireshark-dev: Re: [Wireshark-dev] GSoC 2013 Project Proposal for Root permissions in wireshark
From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 29 Apr 2013 10:34:25 -0700
On Apr 29, 2013, at 9:26 AM, Gerald Combs <gerald@xxxxxxxxxxxxx> wrote:

> One of the problems with this approach is that new, inaccessbile bpf
> devices can be created at any time.

Ultimately, that'a deficiency of OS X - it *should* use cloning BPF devices.