I really love Radio Silence’s UI (based on the screenshot).
Quick thought — for the more-paranoid, would it make sense to let you switch to a whitelist, where only the listed applications are allowed to connect?
Seconded, I'd much rather add applications as needed. Also, the growl notification is a good idea.
And my own small idea: what if I want an application to check for updates? Can I say "allow application to connect for this application session"? Then when the app quits, it won't be allowed to connect out again, unless it's whitelisted.
Quick thought — for the more-paranoid, would it make sense to let you switch to a whitelist, where only the listed applications are allowed to connect?