3 ms·
Arc apps will require explicit permission to communicate with a local network. This can be enforced at the hardware layer by the virtual NIC.
by grun 13y ago
Arc apps will require explicit permission to communicate with a local network. This can be enforced at the hardware layer by the virtual NIC.
- beagle3 13y agoHow do you define local? Is it 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16? I guess that would cover 99% of local networks. I wasn't aware virtualbox has firewalling at the virtual NIC level - my 4.1 doesn't; It's either host-only, bridged, or nat - of which bridged is unlimited, host-only is useless, and nat cannot (as far as I can tell) be firewalled at the virtual NIC level. So how do you do it?
- dannyperson 13y agoEven better would be to require explicit permission to communicate with any site that isn't the app origin. A VM can be put on its own VLAN with a traffic routed through a secure firewall. I don't think Arc is as doomed to be insecure as many are claiming.
- beagle3 13y agoVirtualBox, at least the version I run, cannot do that on its own. You would need to set up the firewall rules on the host. Which is, of course, possible - but not in a cross platform way (linux uses netfilter/iptables, bsd uses pf, windows uses ... I'm not sure what these days, but many users have a 3rd party firewall as well) It isn't doomed to be insecure, but its security, portability and convenience/usability have a nontrivial tradeoff which is ignored by the original description. If it's portable and convenient, it is likely going to be lacking on the security front.