‹ BackHN Continuity

Thread

Hister: A private search engine for the pages you visit and the files you keep

741 points · 202 comments · bookofjoe

  1. computator · · focus · HN ↗
    I'd like to use it, but I'm hesitant to use anything that isn't a reviewed and approved package in my Linux distribution. Even if the chance is 1% that a program I download has malware or security problems that even the author doesn't know about (eg., due to libraries used), odds are that my system's going to be compromised if I run 50 such programs. This extends to browser add-ons, bookmarklets, and extensions too.

    How do other people handle this dilemma?

    Even solution I can think of involves are a great amount of extra work.

    1. nobody42 · · focus · HN ↗
      And it's a proper way to use computer nowadays.

      Apart from high-overhead solutions like VMs and containers, there are seamless and maintenance-free solutions (after the initial setup):

      - systemd service hardening [0] [1]

      pretty powerful, but it's a blacklist approach - whack-a-mole

      - AppArmor [2]

      Whitelist, proactive approach. Contrary to SElinux, it's not a programming language, and could be grasped pretty quickly. I made a tool to easily convert AA logs into usable rules. [3]

      [0] <a href="https:&#x2F;&#x2F;github.com&#x2F;alegrey91&#x2F;systemd-service-hardening" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;alegrey91&#x2F;systemd-service-hardening

      [1] <a href="https:&#x2F;&#x2F;github.com&#x2F;desbma&#x2F;shh" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;desbma&#x2F;shh

      [2] <a href="https:&#x2F;&#x2F;presentations.nordisch.org&#x2F;apparmor&#x2F;" rel="nofollow">https:&#x2F;&#x2F;presentations.nordisch.org&#x2F;apparmor&#x2F;

      [3] <a href="https:&#x2F;&#x2F;github.com&#x2F;nobody43&#x2F;apparmor-suggest" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;nobody43&#x2F;apparmor-suggest

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.