4 ms·
What if you run little snitch and block any communications from obsidian to anything?
by HSO 1y ago
What if you run little snitch and block any communications from obsidian to anything?
- formerly_proven 1y agoLittle snitch can block open(2)?
- 4ndrewl 1y agoI believe they're saying it can open, it just can't send the data anywhere. Seems a little excessive, but here we are.
- notpushkin 1y agoIt still can encrypt everything and demand you pay some ₿₿₿₿.
- lxgr 1y agoIf it can open and write any file on the OS, it's pretty much game over. Too many ways to exfiltrate data even without network/socket access.
- HSO 1y agoWorse, what keeps this from editing the config files for Little Snitch (or similar blockers)?
- TomaszZielinski 1y agoI believe LS has some protections against this. Never tried them, but there are config related security options, incl. protection against synthetic events. So they definitely put some thought into that.
- 4ndrewl 1y agoFile system permissions?
- HSO 1y agoVery, very good point I got lazy Time to crank the paranoidmeter up again ty
- TomaszZielinski 1y agoI treat LS as a privacy/anti-telemetry/anti-accident tool, not as anti malware. Obviously it can detect malware if there’s a connection to some weird site, but it’s more like a bonus than a reliable test. If you need to block FS access, then per app containers or VMs are the way to go. The container/VM sandboxes your files, and Little Snitch can then manage externa connectivity (you might still want to allow connection to some legit domains—-but maybe not github.com as that can be use to upload your data. I meant something like updates.someapp.com)
- elric 1y agoOr firejail. Or QubesOS using a dedicated VM. There are options, but it would still be nice if Obsidian had a more robust security model.
- johnisgood 1y agoI have been using firejail for most of these kind of applications, be it Obsidian, Discord, or the browser I am using. I definitely recommend people start using it.
- dotancohen 1y agoSell it to us! Why do you use specifically firejail? There are so many options, from so many different security perspectives, that analysis paralysis is a real issue.
- johnisgood 1y agoI feel like I should keep track of all my comments on HN because I remember writing a lengthy comment on firejail more than once. I cannot keep doing this. :D For user-space, there is usually bubblewrap vs. firejail. I have not personally used bubblewrap, so I cannot comment on that, but firejail is great at what it does. The last comment was about restricting clipboard access to either X11 or Wayland which is possible with firejail quite easily, so if you want that, you can have that. You can do a LOT more with firejail though. https://wiki.archlinux.org/title/Firejail https://wiki.archlinux.org/title/Firejail https://man.archlinux.org/man/firejail.1 https://man.archlinux.org/man/firejail.1
- wonger_ 1y agoFYI you can search your comment history with hn.algolia.com: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=johnisgood%20firejail&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
- 1y ago