What I want is Little Snitch on steroids built
into the OS where every process,
You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people. What I want is Little Snitch on steroids built
into the OS where every process,
You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people.The real answer IMHO is to control your networking stack outside of your computer instead. Firewall that and you have way better security
You could add large amounts of text and see if the packets increase proportionally.
You can perhaps analyze which apps or extensions are sending packets.
This post doesn’t provide enough information of value
Batching very commonly obscures this kind of UI interaction reporting.
But yeah - whatever you are running on that box better be legit!
To prevent standard data leaking or rather stealing like in this case, linux is a quite solid choice.
But if you think you are a high profile target, you should probably learn how to deactivate Intels ME and co.
And if you are really paranoid, you should assume that there are hardware backdoors. But what do you do then? Build your computer from scratch?
Multiply that by all the multibillion dollar other companies, the tens of thousand open source focused smaller and large companies, the hobbyists, the enthusiasts, the CS professors, the CS undergrad and grad students, the PHD candidates who would be thrilled to discover a flaw on the basis of which they could write their thesis, etc. and I think one can have a fair degree of confidence.
There’s still a decent chance something would be missed. But it’s much smaller than the chance that the proprietary OS owners, whom we know for a fact phone home and have been trying to collect increasing amounts of data, are sending stuff we may not know about.
Many world-class companies depend on Windows, so does that mean you think Windows is safe?
An individual does not have the same access to custom tools, and teams of competent people, that ensure their usage of the Linux ecology is secure.
A recent example: I was investigating using CloudFlare Functions, because I think CloudFlare has world-class security and that “serverless” product avoids many security issues I might have with other solutions. Yet one setup step suggested piping in a script from curl to shell (commonly suggested for install steps!). Even worse, https://github.com/cloudflare/wrangler2 is their CLI tool to help development, and Wrangler is based on the node ecology, which is completely insecurable as an individual developer IMHO (trillion dollar companies can probably secure the dev environment). I use a VM to provide some sandboxing, but it still leaves me feeling icky.
You may instead want to look at the bootstrapping work done using stage0, m2-planet, GNU Mes, etc.
https://bootstrapping.miraheze.org/wiki/Stage0
https://guix.gnu.org/manual/en/html_node/Reduced-Binary-Seed...
It starts with a hex monitor of less than 500 bytes and bootstraps all the way up to gcc, all from source.
... with a compiler you wrote yourself. In assem-- uh, in hexade... no. With toggle switches.