Ask HN: Who Has This Pain?
1–10 of 11 posts
Re: Ask HN: Who Has This Pain?
#2Re: Ask HN: Who Has This Pain?
#3Re: Ask HN: Who Has This Pain?
#4Re: Ask HN: Who Has This Pain?
#5If the downside risks are big and probable enough, use a USB drive and open them on a computer with no internet connection.
Re: Ask HN: Who Has This Pain?
#6Re: Ask HN: Who Has This Pain?
#7I never had that workflow but if I did I would wrap all media players with bubblewrap and that would be inside a highly restricted VM that could only access the domains in questions. The account used to do this on the VM would be single purpose with no sudo/doas permissions and detailed auditd with immutable configuration. No DNS, only /etc/hosts. Only outbound TCP port 443 permitted to the specific IP's in question.…
Re: Ask HN: Who Has This Pain?
#8If it's a sensitive environment like what I'm thinking, you probably have a security officer. What do they say should be the process?
Is the device the sensitive environment? Or is it the network?
Can you have a separate device/network in which to do this?