Hacker News new | past | comments | ask | show | jobs | submit login

Yes. Default deny application firewalls are really powerful tool. It really can take the wind out of large classes of exploits. They can't phone home to exfil data or get follow up command.

It isn't something I'd recommend for everyone, because it is a lot of work and faffing around, but be extremely effective if you are willing to invest in managing it correctly.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: