Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

how to protect against something like this?


1. restrict outbound connections by binary.

2. restrict outbound connections to known malicious IPs or domains.

3. run untrusted code/apps:

   - under a different user
   - or inside a sandbox
   - or in a VM
4. remove exec permissions to temporary directories (/tmp, /var/tmp, /dev/shm)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: