3 ms·
What is the purpose of an "application firewall" in an open source world? If I have the source code and I am curious I just read it. I have yet to see any sou
by 10165 9y ago
What is the purpose of an "application firewall" in an open source world?
If I have the source code and I am curious I just read it. I have yet to see any source code that attempted to obfuscate opening sockets.
Sometimes I run programs with ktrace (strace for Linux folks I guess) and look at the calls.
But truthfully in most cases controlling DNS catches most if not all of today's applications' attempts contact the mothership.
I do not use a third party cache, I maintain a custom root and can use it to block wildcarded domains, something that cannot be done with /etc/hosts. I do make extensive use of the HOSTS file but not for blocking.
I can also redirect traffic to localhost servers where I can log requests and analyze the captured packets. For instance if I want to reverse engineer the protocols used.
In my opinion an "application firewall" is a misnomer. IMHO a "firewall" operates on incoming packets from other computers, not packets originating from the computer running the firewall.
If a Windows user wants to run a "firewall" then IMO they need an additional computer, e.g., a gateway they control.
This is the way to stop the telemetry, IMHO.
I think Microsoft puts some application they call a "firewall" on Windows. IMHO that is misleading, but not surprising considering the source.
In an open source world, in the event a particular user does not "have the time" to read source code or even grep it for clues, chances are that some other user does have the time and compiles all his programs from source. It is always possible that an application's "phoning home" behaviour could be documented by such users in public forums, etc.
What if an application hard codes an IP address? Answer: I see it in the source code. NB: I very rarely see this in practice. Apparently few people can maintain a stable IP.
- subway 9y agoUnfortunately I don't have the time to audit the source of every piece of code I run on my workstation. A project like this to notify me that a process is connecting out to the internet (or another device on my local net), and selectively allow it is a welcome feature.
- cyphar 9y ago> What is the purpose of an "application firewall" in an open source world? Aside from the problems with trying to read the source code for every application on your machine (which I guarantee you have not done), security is all about depth. If an application is compromised or contains network functionality that doesn't do what you would like (and assuming you don't want to have to patch it and rebuild it) then something like this is incredibly useful. Not to mention that (unfortunately) we don't live in a completely free software world, so something like this is very useful if you're forced to run a proprietary program. > But truthfully in most cases controlling DNS catches most if not all of today's applications' attempts contact the mothership. Okay, but what if the application hard-codes the IP address? For an example of a normal project that does this, look at Tor. And even if it doesn't hard-code the IP address how do you dynamically add entries to /etc/hosts? Are you tracing every process on your system and adding entries to /etc/host as soon as the process tries to gethostbyname(2) -- how do you deal with the fact that this will slow down your programs significantly? And what if you want to handle different applications differently? There definitely is utility in a tool that can do all of this dynamically, per-process and also has full support in the Linux kernel already built in without the need to generate /etc/hosts in a horrifically racy way. > IMHO a "firewall" operates on incoming packets from other computers, Yes, and an "application-level firewall" operates on packets from applications. The term firewall is used to describe the "operates on packets" part, not on the "from applications" part of the definition.