5 ms·
> In other words, it won't stop malicious Javascript running in your browser from making an outbound connection, which is the most common way for malware to do
by willstrafach 9y ago
> In other words, it won't stop malicious Javascript running in your browser from making an outbound connection, which is the most common way for malware to do that.
This might be possible, if you start off with deny-all as the default and then start manually adding exceptions as you browse.
- pdonis 9y ago> This might be possible, if you start off with deny-all as the default and then start manually adding exceptions as you browse. Which is unworkable if you visit more than a small number of websites, as I said in another subthread.
- flanbiscuit 9y agoI would like to see internet access treated as an OS permission that need to be expressly granted by the user, same goes for iOS and Android. I wish this was part of the OS and not something I need to go and install 3rd party apps for. I like the idea of deny all by default.
- pdonis 9y ago> I would like to see internet access treated as an OS permission. That would be nice, but it wouldn't fix the problem I've been talking about, because you would have to give your browser the internet access permission, and the OS has no way of knowing which of the connections your browser is making are legitimate and which are not. Only you know that, which means you would have to continually be interrupting your browsing to approve or disapprove connections.
- jason_slack 9y agoLet me ask, seriously: if we take the Great Firewall of China, it does all sorts of packet inspection. Why can't this be applied to personal firewalls and inspect the traffic leaving (or coming in) for malicious content being masked as allowed traffic, etc? There was a company called Packeteer that did traffic shaping/inspection....could any concepts be applied to firewalling as they were to traffic prioritization?
- rjblackman 9y agofor sure it could be done, however it is more complex and resource intensive. probably not good for laptops etc.
- jason_slack 9y agoCan you share insight on how intensive of a task this is?
- dylan604 9y agoand how does one verify the new exception request is trustworthy. it's enough to drive one mad the whole cat/mouse game of trust/deny. the only winning move is not to play.