Hacker News new | past | comments | ask | show | jobs | submit login

Suppose someone gets access to the box. They shouldn't be able to curlbash http://evilscript.sh into the system.

So you really want to lock all outgoing and all incoming except for very specific channels and protocols to controlled endpoints.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: