<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Okay. So question for #linux or #security folks.]]></title><description><![CDATA[<p>Okay. So question for <a href="https://fosstodon.org/tags/linux" rel="tag">#<span>linux</span></a> or <a href="https://fosstodon.org/tags/security" rel="tag">#<span>security</span></a> folks. </p><p>I want to set up a <a href="https://fosstodon.org/tags/nixbook" rel="tag">#<span>nixbook</span></a> (<a href="https://fosstodon.org/tags/nixos" rel="tag">#<span>nixos</span></a>) computer set up as a public access computer. </p><p>I know how to harden the OS to avoid tampering. But how can I filter content?  I'm already getting questions like, how can we prevent people from looking up inappropriate things?</p><p>How would you do it?</p>]]></description><link>https://forum.fedi.dk/topic/d8e621c6-e211-4c1d-a069-31093dc61b15/okay.-so-question-for-linux-or-security-folks.</link><generator>RSS for Node</generator><lastBuildDate>Wed, 03 Jun 2026 09:13:37 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/d8e621c6-e211-4c1d-a069-31093dc61b15.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 May 2026 15:54:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 16:12:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span> <br />Remember to lock down browsers and apps to only use port 53 for dns. And no access to browser configs.</p>]]></description><link>https://forum.fedi.dk/post/https://social.data.coop/users/alf149/statuses/116613445358088723</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.data.coop/users/alf149/statuses/116613445358088723</guid><dc:creator><![CDATA[alf149@social.data.coop]]></dc:creator><pubDate>Thu, 21 May 2026 16:12:44 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 16:03:29 GMT]]></title><description><![CDATA[what means public access computer?<br />webserver or do they access over ssh?<br /><br />ufw and fail2ban maybe?]]></description><link>https://forum.fedi.dk/post/https://mostr.pub/objects/84bc93defaac9eddd36ccfe941e13308855d22d1ce091655d1da0f6cdd89dd71</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mostr.pub/objects/84bc93defaac9eddd36ccfe941e13308855d22d1ce091655d1da0f6cdd89dd71</guid><dc:creator><![CDATA[26a02a0b26c53a3c78277c16491a4a6a75d77542ec29bf73c7213aa2054d0949@mostr.pub]]></dc:creator><pubDate>Thu, 21 May 2026 16:03:29 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 16:01:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span> could use a separate pi-hole as a DNS server and filter using that. All DNS lookups would go through it.  And you can put strict filters there,  Its separate piece of equip the user has 0 access to.  My 2 cents.</p>]]></description><link>https://forum.fedi.dk/post/https://defcon.social/users/970uts1d3/statuses/116613402558396534</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://defcon.social/users/970uts1d3/statuses/116613402558396534</guid><dc:creator><![CDATA[970uts1d3@defcon.social]]></dc:creator><pubDate>Thu, 21 May 2026 16:01:51 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 16:01:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span>  Depends on how technical you are , I would just filter that shit at the layer 3 so a router. Or at layer 7 application and use a firewall tool.  Or setup <a href="https://masto.hackers.town/tags/opnsense" rel="tag">#<span>opnsense</span></a> or <a href="https://masto.hackers.town/tags/pf" rel="tag">#<span>pf</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://masto.hackers.town/users/nixfreak/statuses/116613399514748520</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://masto.hackers.town/users/nixfreak/statuses/116613399514748520</guid><dc:creator><![CDATA[nixfreak@masto.hackers.town]]></dc:creator><pubDate>Thu, 21 May 2026 16:01:05 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 16:00:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span> You may use the /etc/hosts file if you're wanting to block sites from the device itself, problem being you'd most likely have to manually maintain it / add it as a nixOS package and then have to auto update your hosts.</p>]]></description><link>https://forum.fedi.dk/post/https://fosstodon.org/users/Techwizz/statuses/116613398715693169</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fosstodon.org/users/Techwizz/statuses/116613398715693169</guid><dc:creator><![CDATA[techwizz@fosstodon.org]]></dc:creator><pubDate>Thu, 21 May 2026 16:00:52 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 15:58:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span> There are certain aspects you can look into like DNS filtering and blacklisting.</p><p>However, after some decades in IT I can tell you that it is virtually impossible to prevent all conceivable misuse.</p><p>If you have a browser that is not in a *whitelist* mode, they will access stuff.</p><p>Just as an example, for  cases like these, I have a VPN machine with a dedicated IP somewhere* I can ask to reverse-proxy stuff for me.</p><p>* Not gonna tell you <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61c.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--stuck_out_tongue_winking_eye" style="height:23px;width:auto;vertical-align:middle" title="😜" alt="😜" /></p>]]></description><link>https://forum.fedi.dk/post/https://norden.social/users/ftranschel/statuses/116613388134766567</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://norden.social/users/ftranschel/statuses/116613388134766567</guid><dc:creator><![CDATA[ftranschel@norden.social]]></dc:creator><pubDate>Thu, 21 May 2026 15:58:11 GMT</pubDate></item><item><title><![CDATA[Reply to Okay. So question for #linux or #security folks. on Thu, 21 May 2026 15:58:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/codemonkeymike%40fosstodon.org">@<span>codemonkeymike</span></a></span> <br />A local docker with pihole as the DNS (filters could be controlled from a git repo, haven’t tried this)</p>]]></description><link>https://forum.fedi.dk/post/https://social.data.coop/users/alf149/statuses/116613387799499909</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.data.coop/users/alf149/statuses/116613387799499909</guid><dc:creator><![CDATA[alf149@social.data.coop]]></dc:creator><pubDate>Thu, 21 May 2026 15:58:06 GMT</pubDate></item></channel></rss>