‹ BackHN Continuity

Thread

Ask HN: Who Has This Pain?

3 points · 6 comments · swk-phil

  1. Bender · · focus · HN ↗
    I never had that workflow but if I did I would wrap all media players with bubblewrap and that would be inside a highly restricted VM that could only access the domains in questions. The account used to do this on the VM would be single purpose with no sudo/doas permissions and detailed auditd with immutable configuration. No DNS, only /etc/hosts. Only outbound TCP port 443 permitted to the specific IP's in question. Everything else rejected and logged. No sensitive files on the hypervisor.
    1. xp84 · · focus · HN ↗
      This is the way.^
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.