"Workstation" Product defaults to wide-open firewall

Bastien Nocera bnocera at redhat.com
Tue Dec 9 15:32:28 UTC 2014



----- Original Message -----
> On Tue, 9 Dec 2014 10:09:07 -0500 (EST)
> Bastien Nocera <bnocera at redhat.com> wrote:
> 
> > 
> > 
> > ----- Original Message -----
> > > On Mon, 8 Dec 2014 05:45:56 -0500 (EST)
> > > Bastien Nocera <bnocera at redhat.com> wrote:
> > > 
> > > > No, because that'd be awful UI.
> > > 
> > > Is it really so awful to ask a user:
> > > "Do you want to expose Eclipse to the network ?" (of course worded
> > > in a better way than my poor English skills can do).
> > 
> > Probably not, but it's not implementable in the current state of
> > things.
> 
> Understood.
> Do we have a way to get there ?
> (trying to be constructive here)

1. Land kdbus
2. Implement sandboxing support, including a way for system services
   to securely identify applications talking to them, and/or block
   particular capabilities (such as network access, filesystem access, etc.)
3. Profit!


More information about the devel mailing list