• 0 Posts
  • 18 Comments
Joined 1 year ago
cake
Cake day: June 3rd, 2023

help-circle




  • I disagree with one of their points

    Network firewalls can also be configured to deny inbound and outbound traffic to and from the physical interface. This remedy is problematic for two reasons: (1) a VPN user connecting to an untrusted network has no ability to control the firewall and (2) it opens the same side channel present with the Linux mitigation.

    Sure, they can’t control the network firewall, but why would you do that when you can change your local firewall? Set an iptables rule to drop all traffic going out the physical interface that isn’t destined for the VPN server. I’m 70% sure some vpn clients do this automatically.


  • For your specific case, sure, but for that quote, I haven’t had those issues in years. I’m also running Mint, but on a desktop and have had zero issues. Mouse “just works,” extra monitors “just work,” and (most surprisingly to me), printer “just works,” games on Steam “just work” with all they’ve done with Proton. I switched to Google docs a long time ago, so at least for me the Office thing isn’t relevant. It natively supports discord, my password manager, Spotify, everything I’ve wanted. I switched my wife’s Mac to it years ago since it had gotten slow from bloat, and she’s been just fine despite not being very tech literate.