It's a step in the right direction; it just isn't much of a step. Ultimately I think we need a fine-grained capability system, where every process runs in a sandbox which can only see the resources I choose to grant it. Access to the specific hosts ought to be resources... and I should be able to provide dummy resources so that recalcitrant apps which refuse to run without the ability to call home can be run in an environment equivalent to a "hellban".