Ask HN: What's the best way to secure your workstation?
18 by bccdee | 13 comments on Hacker News.
Here's a very plausible threat: Some developer with a left-pad package, some dependency-of-a-dependency, injects malware into their library. A developer (who is broadly trustworthy) updates their package's dependencies without auditing them properly, and the malware ends up in a VSCode plugin that you use. You open VSCode, your system is infected. We know this sort of malware is making its way onto package repositories [1]. We know people are falling for these attacks. How do we protect ourselves against this family of threats? [1]: https://ift.tt/3eIvIio We could trust nothing beyond our base system and our browser, and refuse to use any code we don't fully audit, but this would be an impossibly austere way to live. I expect most of us, when pressed, would admit that we're trusting much more code than we would like to. The alternative is sandboxing, using a lightweight option like firejail (which I use) or a totalizing system like QubesOS. But these systems are awkward to use, and have their own drawbacks. What's the bar for reasonable security, in your opinion? How do you secure your workstation without living like a monk?
Subscribe to:
Post Comments (Atom)
Pages - Menu
About Me
Blog Archive
-
▼
2021
(7588)
-
▼
November
(659)
- New top story on Hacker News: ‘The Collected Prose...
- New top story on Hacker News: Synthetic tissue can...
- New top story on Hacker News: The American Prison ...
- New top story on Hacker News: German Court Rules A...
- New top story on Hacker News: Silbo Gomero: ‘Speci...
- New top story on Hacker News: Searchable flight lo...
- New top story on Hacker News: Cancer therapy from ...
- New top story on Hacker News: Reducing an LTO Linu...
- New top story on Hacker News: AWS Outposts
- New top story on Hacker News: New research links p...
- New top story on Hacker News: UI/UX Designer at Ni...
- New top story on Hacker News: Proposed Bill to Out...
- New top story on Hacker News: An Illustrated Guide...
- New top story on Hacker News: Moving Castles: Modu...
- New top story on Hacker News: FBI access levels to...
- New top story on Hacker News: DESQview/X: The forg...
- New top story on Hacker News: The US C-Band Spectr...
- New top story on Hacker News: Scaling Kafka at Hon...
- New top story on Hacker News: AWS Nitro SSD – High...
- New top story on Hacker News: Ten Million Deaths a...
- New top story on Hacker News: Back End Developers ...
- New top story on Hacker News: AWS Redshift Serverless
- New top story on Hacker News: Crises of Elite Comp...
- New top story on Hacker News: Ex-Google workers su...
- New top story on Hacker News: Satellites Reveal Ar...
- New top story on Hacker News: Researchers find xen...
- New top story on Hacker News: Researchers Find Fin...
- New top story on Hacker News: Proof-of-Stake and S...
- New top story on Hacker News: Show HN: An AWS Savi...
- New top story on Hacker News: “It's not peaches an...
- New top story on Hacker News: Team builds first li...
- New top story on Hacker News: Motion (YC W20) is h...
- New top story on Hacker News: Pull Through Cache R...
- New top story on Hacker News: Asmrepl: REPL for x8...
- New top story on Hacker News: Google Chromium, san...
- New top story on Hacker News: Music is a negative ...
- New top story on Hacker News: The case of the recu...
- New top story on Hacker News: AppFlowy: an open-so...
- New top story on Hacker News: The poetry and brief...
- New top story on Hacker News: Show HN: Factorio Bl...
- New top story on Hacker News: Digging for Utopia
- New top story on Hacker News: Breakthrough, PhD st...
- New top story on Hacker News: The Inherent Limitat...
- New top story on Hacker News: Show HN: Md2blog – A...
- New top story on Hacker News: How the Ancient Roma...
- New top story on Hacker News: A Constitutional Con...
- New top story on Hacker News: Generally Intelligen...
- New top story on Hacker News: Herbs and Spices Mig...
- New top story on Hacker News: How to Save a Ski Town
- New top story on Hacker News: Designer Diary: The ...
- New top story on Hacker News: Anthocyanins
- New top story on Hacker News: Command Palettes: Ho...
- New top story on Hacker News: Ask HN: Have you not...
- New top story on Hacker News: Colobot, an RTS game...
- New top story on Hacker News: Ask HN: Know any non...
- New top story on Hacker News: Update on Omicron
- New top story on Hacker News: Why don’t we just op...
- New top story on Hacker News: South African medica...
- New top story on Hacker News: The truth about turb...
- New top story on Hacker News: McKinsey taught Big ...
- New top story on Hacker News: Labors of Love: Tran...
- New top story on Hacker News: The Fuel of Philosop...
- New top story on Hacker News: Today’s Disneyland i...
- New top story on Hacker News: The slowest SR-71 Bl...
- New top story on Hacker News: BMW removing touchsc...
- New top story on Hacker News: A small Scheme imple...
- New top story on Hacker News: Ask HN: What's the b...
- New top story on Hacker News: Permutation-Invarian...
- New top story on Hacker News: Rare Greek Variables
- New top story on Hacker News: A Utopia of Useful T...
- New top story on Hacker News: Five Books That Chan...
- New top story on Hacker News: A prioritised micro-...
- New top story on Hacker News: More Cash Invested i...
- New top story on Hacker News: My friends Instagram...
- New top story on Hacker News: Making a feedback fo...
- New top story on Hacker News: Explainer: .DS_Store...
- New top story on Hacker News: The Myth of Multitas...
- New top story on Hacker News: Ask HN: Why is Docus...
- New top story on Hacker News: Tell HN: GitHub is d...
- New top story on Hacker News: Spirituality Shaped ...
- New top story on Hacker News: SQLite Strict Tables
- New top story on Hacker News: SQLite Release 3.37.0
- New top story on Hacker News: Show HN: A music pla...
- New top story on Hacker News: Godot Engine – Multi...
- New top story on Hacker News: Reality shifting: an...
- New top story on Hacker News: 2021 Tesla Model Y r...
- New top story on Hacker News: Everyone’s Moving to...
- New top story on Hacker News: Comparison of Operat...
- New top story on Hacker News: Pinning in Plain Eng...
- New top story on Hacker News: LemonScript: A typed...
- New top story on Hacker News: Cognitive distortion...
- New top story on Hacker News: Jerry (YC S17) Is Hi...
- New top story on Hacker News: Procrastination and ...
- New top story on Hacker News: Ask HN: What are the...
- New top story on Hacker News: AWS price reduction ...
- New top story on Hacker News: California port truc...
- New top story on Hacker News: PyTorch: Where we ar...
- New top story on Hacker News: Omicron Variant: Ear...
- New top story on Hacker News: New in C# 10: Easier...
- New top story on Hacker News: EU tech sector fight...
-
▼
November
(659)
Labels
- 'Dedication 5' (1)
- "Miley Cyrus (1)
- Ander Herrera (1)
- Bundesliga (1)
- Catherine Zeta Jones (1)
- CFL (1)
- Chennai Express (1)
- Chris Brown (2)
- Eid Mubarak Wishes (1)
- Electric Zoo (1)
- Hacker News (7613)
- James Spader (1)
- kim jong un pochonbo electronic ensemble kenji fujimoto hyon song-wol pictures (2)
- Lamar Odom (1)
- Lavabit (2)
- Lukaku (1)
- Michael Girgenti (1)
- michael jackson games michael jackson songs michael jackson pictures michael jackson videos michael jackson (1)
- NAACP (21)
- Nexus 4 Price Drop Available to Some Past Buyers (1)
- Nintendo 2DS (1)
- Powerball winner: 'I don't want to work ... for the rest of my life' (1)
- Pretty Little Liars (1)
- Ribery (1)
- Riley Cooper (1)
- Satyagraha (1)
- Seamus Heaney (2)
- Sylvie van der Vaart (1)
- Taste of the Danforth (1)
- UEFA (1)
- US PGA (1)
- Yasin Bhatkal (1)
No comments:
Post a Comment