[Return]

Report a post

Preview
>It's funny when /g/-adjascent people sperg out over security and hardening systems. Downloading a million random poorly maintained programs just increases your attack surface and vulnerability to dependency and chain attacks. You want LESS, always.

assuming you are talking about the image you posted
i think you got the wrong target audience. if you host any sort of service, or better yet a whole network of services. you are no longer at just your desktop where you can memorize everything running and can slap a firewall and run opensource software.
on the enterprise network you are forced to work with insecure software or closed source trash. couple that with a whole staff of people to work on your enterprise network, now u got more issues.
think of it as a trade off. the enterprises cant afford to move slower and watch to make sure every dev written good configs for there network service. so they have to use higher level monitoring tools to contain, detect, fix, some fucked up shit. at a certain point you will excited the capacity of abstractions.

>because they didn't realize a bumfuck vibe coded program somehow kept a port open to the internet.
exactly! now if you have like in OP's pic, things to sandbox software and monitor the network, you can detect and contain this. having layers of security/detection may or may not be better then way less/none and just hand audit with open source. its a trade off.

if you actually are talking about personal security like most people in this thread are. yeah the chart you posted is useless and will cause more issues the help.
but some of the same principles still apply and you have more control over the hand audit and what you keep in your head. there is better ways then what people prepose to achieve this.
here is what should ACTUALLY be done. get qubes.
yup that is about it. you must have 2 devices you can trust.
device 1, your router
device 2, your main computer.
the rest falls out for free when you understand networking.
like network interfaces, subnetting, vpn, trunking, etc.
with qubes u can seamlessly spawn in a VM that auto routes everything thru TOR. or have a VM that has a VPN connection to your router management and other network services you have and can manage them.
then you can have the VMs default network not allow to talk to anything and just go out to the internet only.

if your shitty heyuri VM gets hacked, they cant get accesses your webcam or mic unless u give ur VM. they will end up stuck and deleteing your heyuri save files but cant assess your PRONZ VM. that is what you get for downloading little Alice and running it, even over wine you will still get PWNd.

many other little thigns i did not talk about like disabling hyper threading for qubes or flashing coreboot/dasharo on your comptuer. but there is many other little things u can do.
fun fact, there is a intel motherboard that supports 12th gen CPUs and ddr5 that you can get itel ME disabled via dasharo. stay safe and learn unix
Post number No.194674
Board Off-Topic@Heyuri
Optional. Describe what's wrong with it.