Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’ve grown to depend on little snitch for this sort of thing. Always run in either Alert or Deny mode.

It is a little wild how many things expect to communicate with the internet, even if you tell them not to.

Example: the Cline plugin for vscode has an option to turn off telemetry, but even then it tries to talk to a server on every prompt, even when using local ollama.



A simple zero-config alternative using Linux-native containers seems to be sandbox-venv [1] for Python and sandbox-run [2] for npm ...

[1]: https://github.com/sandbox-utils/sandbox-venv [2]: https://github.com/sandbox-utils/sandbox-run


I agree, it's very valuable in these situations, although it can only minimize damage. For Littlesnitch/OpenSnitch users: avoid allow rules that apply to all apps. Malware can and has used even trusted websites like Github Gists to expose secrets extracted.

In any case, even if your firewall protects you, you'll still have to treat the machine as compromised.


OpenSnitch like functionality should come installed and activated by default.


specially interpreters: python, perl, npm, etc.

https://github.com/evilsocket/opensnitch/wiki/Rules#best-pra...


... And people think I'm crazy for complaining about automated build systems that expect Internet access....


Yep, Malwarebytes WFC really eases my mind.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: