4 ms·
Indeed, the test you suggest would be a lot more thorough. Cool description, thanks! I feel like my test somewhat assumes that the OS plays by the rules and do
by anticristi 3y ago
Indeed, the test you suggest would be a lot more thorough. Cool description, thanks!
I feel like my test somewhat assumes that the OS plays by the rules and doesn't desperately hide its communication.
In contrast, your test assumes like the OS is somewhat adversarial, e.g., the vendor of the OS ships it with a malware ... or AdTech partnership of some kind. :)
- LinuxBender 3y agoyour test assumes like the OS is somewhat adversarial This, and it makes the testing easier to reproduce for multiple images. This is useful if one has to perform forensics in dirty sandboxes on a dirty-net on a daily basis but is also useful for comparing the behavior of multiple releases of an OS to see "which one of these is not like the other". Sometimes changes are subtle so it can help to have an external method/device to diff DNS and firewall logs. I find this useful for finding changes that are not clearly documented in git. I should add in fairness to the OS developers it is rarely malevolent but rather they quietly fixed something embarrassing. DNS logging can also be useful for finding applications that are lazy-coded to not cache results for the TTL specified by the record. I fought many battles ages ago with Java itself, not developer apps on top of Java on this matter.