Hister: A private search engine for the pages you visit and the files you keep
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Hister: A private search engine for the pages you visit and the files you keep
Unofficial Hacker News client; not affiliated with Y Combinator.
computator · · focus · HN ↗
How do other people handle this dilemma?
Even solution I can think of involves are a great amount of extra work.
nobody42 · · focus · HN ↗
Apart from high-overhead solutions like VMs and containers, there are seamless and maintenance-free solutions (after the initial setup):
- systemd service hardening [0] [1]
pretty powerful, but it's a blacklist approach - whack-a-mole
- AppArmor [2]
Whitelist, proactive approach. Contrary to SElinux, it's not a programming language, and could be grasped pretty quickly. I made a tool to easily convert AA logs into usable rules. [3]
[0] <a href="https://github.com/alegrey91/systemd-service-hardening" rel="nofollow">https://github.com/alegrey91/systemd-service-hardening
[1] <a href="https://github.com/desbma/shh" rel="nofollow">https://github.com/desbma/shh
[2] <a href="https://presentations.nordisch.org/apparmor/" rel="nofollow">https://presentations.nordisch.org/apparmor/
[3] <a href="https://github.com/nobody43/apparmor-suggest" rel="nofollow">https://github.com/nobody43/apparmor-suggest