‹ BackHN Continuity

Thread

Ask HN: Who Has This Pain?

3 points · 6 comments · swk-phil

  1. anigbrowl · · focus · HN ↗
    If the downside risks are big and probable enough, use a USB drive and open them on a computer with no internet connection.
    1. merona_io · · focus · HN ↗
      imma do that!
  2. Bender · · focus · HN ↗
    I never had that workflow but if I did I would wrap all media players with bubblewrap and that would be inside a highly restricted VM that could only access the domains in questions. The account used to do this on the VM would be single purpose with no sudo/doas permissions and detailed auditd with immutable configuration. No DNS, only /etc/hosts. Only outbound TCP port 443 permitted to the specific IP's in question. Everything else rejected and logged. No sensitive files on the hypervisor.
    1. xp84 · · focus · HN ↗
      This is the way.^
  3. [deleted] · · focus · HN ↗

    [deleted]

  4. yellow_lead · · focus · HN ↗
    Where are those media files from? It's pretty unlikely to encounter an RCE in media files these days. but if you are an important enough target, one could be crafted for your device or software (i.e vlc)
  5. rovr138 · · focus · HN ↗
    What is a 'sensitive environment' in this case?

    If it's a sensitive environment like what I'm thinking, you probably have a security officer. What do they say should be the process?

    Is the device the sensitive environment? Or is it the network?

    Can you have a separate device/network in which to do this?

  6. [deleted] · · focus · HN ↗

    [deleted]

  7. lpsatwork · · focus · HN ↗

    [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.