4 ms·
> lacks features such as per process rules. You have to do hacks like assign rules to users From a practical standpoint, I find it hard to imagine that the cos
by jb613 10y ago
> lacks features such as per process rules. You have to do hacks like assign rules to users
From a practical standpoint, I find it hard to imagine that the cost of added complexity for configuring application rules per user would outweigh the benefits of simply configuring them system wide. I remember the days of terminal clients logging into mainframes but all I see are single user desktops. Things like location on the network matter more in an application firewall than which user is accessing the desktop.
- 45h34jh53k4j 10y agoI didn't mean per user vs per system; in as much a per process image. ie: firefox can get out to *, but sandbox can not. If you have never used something like Little Snitch on MacOS it is very surpassing to see all the outgoing connections from processes. It returns some control to the user to block cloud services, application dial home, etc. Being able to interactively allow/deny access to resources (say via hostname or via IP) per connection per process (image?) is very valuable. This is hard to do in linux. Several good solutions to do this in MacOS and Windows.