4 ms·
> Really, what we are talking about is this: what if, when Zoom sent telemetry to Facebook without your authorization or knowledge apparently because they used
by softwarebeware 5y ago
> Really, what we are talking about is this: what if, when Zoom sent telemetry to Facebook without your authorization or knowledge apparently because they used some library and didn't realize it did that, your host firewall told you that this random application was shipping your most personal secrets directly to Mark Zuckerburg and, even better, prevented it doing so until you considered the question?
Yes, please! That would be amazing
- gruez 5y agoThose already exist, eg. littlesnitch on mac. As it relates to this problem though (ie. zoom), such program would get annoying pretty quick, because they'll be connecting to random IPs every time (different relay servers/peers), so you eventually get tired of the alerts and whitelist everything.
- Nextgrid 5y agoI find huge value in using these as a blacklist - this won't protect against a zero-day or unknown malware, but it will absolutely protect against the known, repeat offenders. Having all Facebook and Google domains & IPs blacklisted will already do wonders for your privacy. You can whitelist the browser if you need to access such services while making sure trackers in other apps still can't talk to them.
- srijan4 5y agoI think the alerts would have to be at a higher level hierarchy than plain URLs or domains. I'm imagining a categorized whitelist of domains based on purpose (essential, telemetry, ads) which the user would choose from at first run, and the program would just block the other domains without asking again and again.
- selfhoster11 5y agoZoneAlarm did this back in the day. I was puzzled even back then about why so many applications wanted to dial out to this address or another. Today it would probably scream non-stop.
- thg 5y agoHave a look at OpenSnitch: https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch Never used it myself, only remembering it from my thesis days about essentially the same topic. I see they made the jump away from Python to Go and I'm also somewhat surprised the project is not only still active, but appears to have matured nicely. Guess I'll have to check it out now! Here's the initial HN discussion of OpenSnitch from 5 years ago: https://news.ycombinator.com/item?id=14245270 https://news.ycombinator.com/item?id=14245270
- cookiengineer 5y agoI'm using OpenSnitch for over 2 years now on my desktop systems. Can fully recommend. I've set the default timeout to 30 seconds so I have time to decide/chime in, and the default action to one-time deny so it doesn't mess up my rules when I'm not at the computer. Compared to previous Linux firewalls it's able to filter by binary and command line path (e.g. is able to differ between python server.py and python malware.py), which I think is pretty amazing. Though I have to say due to the nature of wine, allowing things in nice rules there is a little harder (cause everything uses rundll32.dll anyways :-/ ).
- dhaavi 5y agoThen check out the Portmaster Application Firewall: https://safing.io/portmaster/ https://safing.io/portmaster/ Disclaimer: I’m Co-Founder/CTO of Safing, the company behind the Portmaster. You can ask me questions here - I have notifications enabled.