3 pointsby swk-phil2 hours ago3 comments
  • Benderan hour ago
    I never had that workflow but if I did I would wrap all media players with bubblewrap and that would be inside a highly restricted VM that could only access the domains in questions. The account used to do this on the VM would be single purpose with no sudo/doas permissions and detailed auditd with immutable configuration. No DNS, only /etc/hosts. Only outbound TCP port 443 permitted to the specific IP's in question. Everything else rejected and logged. No sensitive files on the hypervisor.
  • anigbrowlan hour ago
    If the downside risks are big and probable enough, use a USB drive and open them on a computer with no internet connection.
  • an hour ago
    undefined