TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Is Ubuntu Linux spying on you?

6 点作者 anticristi超过 1 年前

2 条评论

LinuxBender超过 1 年前
<i>Is Ubuntu Linux spying on you?</i><p>It has in the past but I would be somewhat surprised if they did not learn from the blow-back unless they have entirely new leadership.<p>One small suggestion, instead of creating a systemd unit file on the host your are monitoring I would suggest doing your captures on your router and also force all DNS through that router <i>using the nat table to capture 53, 853 and blackhole all the commonly used DoH&#x2F;DoT servers</i>. Despite theories suggested on here in the past none of the common DoH servers use shared CDN IP&#x27;s. After blocking those IP&#x27;s then reboot the host to clear application DNS cache.<p>Boot up all the mainstream distributions to see which ones are being chatty. Another one that may be fun to play around with is the latest Fedora beta. <i>No [Spoilers].</i> Have fun with it, don&#x27;t just use tcpdump. Instead give bogon IP&#x27;s for some of the names you see being requested after rebooting the VM and watch what breaks then add that to your blog. Some apps may have hard coded IP&#x27;s to fall back on like Windows has done since at least XP. QubesOS is one good way to try each of them out including their beta versions and release candidates. The testing should be after a clean installation from the ISO and then again after a OS update and reboot otherwise it could be applications you installed creating red herrings. The reason for testing after ISO and then again after OS update is to see if someone changed their minds about telemetry or to see if people are playing cat-and-mouse when people document findings.
评论 #37453244 未加载
elesiuta超过 1 年前
I created picosnitch which may be of interest if you also want to see the executable behind each request, this way you wouldn&#x27;t need to disable NextCloud, Dropbox, Slack, etc (the UI doesn&#x27;t have negative filtering, yet, but everything is just an entry in a sqlite db).<p>It also gets the hash of each executable, which can be useful if you&#x27;re running any containers with different versions of the same executable which would otherwise appear to have the same path.