4 ms·
The reddit thread raises a good question I have often wondered. What is my best option for an application level firewall? I want to deny network connections by
by c618b9b695c4 5y ago
The reddit thread raises a good question I have often wondered. What is my best option for an application level firewall? I want to deny network connections by default and specifically enable who can speak to the outside world.
- miles 5y agoOpenSnitch[1] is mentioned[2] in the reddit thread and was most recently featured on HN last year[3]. [1] https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch [2] https://old.reddit.com/r/linux/comments/od3h8b/audacity_may_collect_data_necessary_for_law/h3yzi8s/ https://old.reddit.com/r/linux/comments/od3h8b/audacity_may_... [3] https://news.ycombinator.com/item?id=22206116 https://news.ycombinator.com/item?id=22206116
- simcop2387 5y agoFor linux, check out firejail for isolating it.
- pmontra 5y agoI didn't know about firejail. Thanks. The gist of it is sudo apt install firejail firejail audacity I guess that the line net none in /etc/firejail/audacity.profile prevents any network connections. And man firejail for many useful functionalities.
- iliketrains 5y agoOn Windows I use henrypp/simplewall. It is lightweight UI on top of Windows Filtering Platform. My only complaint is to all the self-updating programs that keep changing its binary and I need to re-enable them periodically...
- sneak 5y agoNetlimiter on Windows, Little Snitch on macOS.
- throwawayboise 5y agoRun it under a different user and firewall that user off from network access.
- lioeters 5y agoOn macOS, LuLu: https://objective-see.com/products/lulu.html https://objective-see.com/products/lulu.html
- matheusmoreira 5y ago> I want to deny network connections by default and specifically enable who can speak to the outside world. I also want to filter the network data. I want my firewall to inspect what the software is sending over the network and delete, randomize or nullify all data that isn't strictly necessary for it to perform the desired function. Like uBlock Origin but for the network stack. This would enable normal operation of the software while also at least partially subverting the "legitimate business interests" of these corporations.
- alpaca128 5y agoCould also work with file access. Most applications never need to access the whole filesystem. My browser mostly needs access to the profile-specific data and the downloads folder. A music player doesn't need access to anything outside the music directory and also no networking unless maybe that one URL it uses to load album cover images. Although I'd only prefer this approach if it's actually done right. Android, Flatpak etc. mostly showed ways to do it badly.
- matheusmoreira 5y agoAgreed. We need ways to filter every Linux system call. Not just disallow the system calls themselves. We need the ability to apply policies to parameters and filter I/O in a transparent way.
- jfrunyon 5y agohttps://en.wikipedia.org/wiki/Systrace https://en.wikipedia.org/wiki/Systrace https://en.wikipedia.org/wiki/Linux_Security_Modules https://en.wikipedia.org/wiki/Linux_Security_Modules
- jfrunyon 5y agohttps://wiki.ubuntu.com/AppArmor https://wiki.ubuntu.com/AppArmor ???
- phone8675309 5y ago