Opensnitch, application level interactive firewall, heading into Debian
people.skolelinux.org
people.skolelinux.org
OpenSnitch is a GNU/Linux port of the Little Snitch application firewall - https://news.ycombinator.com/item?id=31876220 - June 2022 (75 comments)
OpenSnitch is a GNU/Linux port of the Little Snitch application firewall - https://news.ycombinator.com/item?id=22206116 - Jan 2020 (131 comments)
OpenSnitch: LittleSnitch clone for Linux - https://news.ycombinator.com/item?id=16566823 - March 2018 (6 comments)
OpenSnitch – A Linux clone of the Little Snitch application firewall - https://news.ycombinator.com/item?id=14245270 - May 2017 (103 comments)
To block network access: firejail, unshare, or ip-nets jail if you like to get your hands dirty.
To limit bandwidth you can use trickle, wondershaper or again use ip tools.
If you don't mind some work SELinux can do this and so does AppArmor which is probably already included in your distro.
Note that Linux has application firewalling built in as part of kernel namespaces.
Edit: forgot to add, new application containers such as snap have a built in system for this and more - just like how its done on phones.
I'm thinking of a situation where I want to run a precompiled binary, but only want it to talk to an other container and not the outside world. How would I do that?
docker run --network=none x
Local only docker network create --internal int1
docker run --network=int1 xyes, and not many of them allow inspection on the level that i am interested in.
for example, counting bandwith per interface when i really care about speed and accumulated bandwith that goes the ISP.
https://wiki.debian.org/PrivacyIssues#Detection_tools
Lots of different examples of those violations on the page too.
Edited to add: Linux is also supported, but IMHO this is the wrong target group for that. Not here to draw users from OpenSnitch, as it is great and fits perfectly for its use case. Very nice to have it included in debian. Big win for privacy!
You can group connections by country in the meantime to get a feel for where things are going. (You can also group by multiple values for a bit more detail.)
https://github.com/evilsocket/opensnitch/wiki/Dependencies-a...
Seems like the Linux kernel enforces the firewall rules:
https://github.com/evilsocket/opensnitch/wiki/Why-OpenSnitch...
Yea, for outbound packets.
Nope, for inbound packets.
BSD and Windows provides both; Linux, not so much.
As has been described in detail on many[1] places[2] on the internet. Apple are NOT spying on you. This is a VLU feature. Otherwise known as "Siri Suggestions".
Don't want the callback to Apple on images, disable "Siri Suggestions". End of story.
The false attempts at linking Siri to the discontinued Apple CSAM is pure BS, FUD.
[1] https://eclecticlight.co/2022/04/08/how-to-enable-use-and-fi... [2] https://eclecticlight.co/2023/01/18/is-apple-checking-images...
Edit to add:
1) In fact, Apple make this crystal clear if you can be bothered to look into "About Search & Privacy" in System Settings before firing up your blog editor and composing a completely unsubstantiated FUD-fueled rant ....
"About Search & Privacy"
You Have Choice and Control
If you do not want Suggestions from Apple to send your information to Apple, you can disable that option by going to System Settings > Spotlight > Search Results and deselecting Siri Suggestions. You can disable Safari Suggestions in Safari by going to Safari > Settings > Search and deselecting Include Safari Suggestions.
2) In addition, in relation to submitted information, Apple also make it crystal clear that IF you leave the feature enabled the data is not personally identifiable:
Any information sent to Apple does not identify you, and is associated with a 15-minute random, rotating, device-generated identifier. This information may include location, topics of interest (for example, cooking or football), your search queries, suggestions you have selected, apps you use and related device usage data. This information does not include search results that show files or content on your device. If you subscribe to music or video subscription services, the names of these services and the type of subscription may be sent to Apple. Your account name, number and password will not be sent to Apple.
This information is used to process your request and provide more relevant suggestions and search results, and is not linked to your Apple ID, email address or other data Apple may have from your use of other Apple services.
https://www.forbes.com/sites/jeanbaptiste/2019/07/30/confirm...
First time you hear about this? Well, random strangers always rushing in to defend Apple and question the reporters integrity and motives are why we are where we are today...
For every "random stranger defending Apple", there are about 100 random strangers rushing in to bash Apple.
Bashing Apple is an age-old bandwagon.
I'm not saying Apple are perfect. Not by any means.
What I am saying is that if you are going to go off on a rant about Apple, make a damn effort to substantiate it by facts. Actual facts, not "something a friend told me", not an "experience of one", not making random unsubstantiated pure-BS extrapolations (e.g. Siri vs CSAM) etc. etc.
Unsubstantiated Apple bashing is not helping anyone. It also makes the Apple basher themselves looks like an idiot when their FUD is easily disproved.