Remix.run Logo
yipinwong 5 hours ago

Very security engineer minded approach.

I block every port for VPS, then open one by one. Same approach here with files.

The only downside I see here is, knowing which one to allow. For ports, it's easy, but files can have many different extensions.

Apps/CLIs, etc create files with extensions you never encountered before, which can cause issues.

Other than that, I like the apporach

der_gopher 3 hours ago | parent [-]

I like the analogy with ports, I also do the same - ufw deny all :)