Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm no longer a Mac user, but LS was an essential part of my system where I was. Does anyone know of a similar product for Linux?



There is OpenSnitch ( https://github.com/evilsocket/opensnitch ) but I'm not sure how well it compares?


This app is a decent reason to add signature checking to distros. Though until we're off of X11 the application doing the connecting can just press the button on OpenSnitch itself!

Unless you're on Wayland, OpenSnitch is totally vulnerable. One workaround would be to have OpenSnitch stop the requesting process before displaying the prompt, but if there's a configuration panel any application can just add the exception ahead of time anyway.


Wasn't this mentioned here a couple weeks ago? https://opensnitch.io/



more like a couple months then :) thanks


Not a firewall, but Firejail is a great sandboxing tool for Linux.

https://firejail.wordpress.com/


Not much in the realm of Linux, to be honest. You'd probably get more security maintaining a SELinux setup on your system and running a hardened kernel.


That's a different concern, though. Or does SELinux allow you to specify "process X may speak to domain Y with HTTP, but not to any other domains"?


Do you have any reference material that goes more in depth?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: