Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248309 > unrolled thread

Disable connections to Internet without user's consent

Started byAndrea Monaco <andrea.monaco@autistici.org>
First post2022-05-17 23:20 +0200
Last post2022-05-18 20:00 +0200
Articles 7 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  Disable connections to Internet without user's consent Andrea Monaco <andrea.monaco@autistici.org> - 2022-05-17 23:20 +0200
    Re: Disable connections to Internet without user's consent IL Ka <kazakevichilya@gmail.com> - 2022-05-18 00:40 +0200
    Re: Disable connections to Internet without user's consent Dan Ritter <dsr@randomstring.org> - 2022-05-18 01:00 +0200
      Re: Disable connections to Internet without user's consent Cindy Sue Causey <butterflybytes@gmail.com> - 2022-05-18 05:50 +0200
        Re: Disable connections to Internet without user's consent <tomas@tuxteam.de> - 2022-05-18 06:30 +0200
        Re: Disable connections to Internet without user's consent Dan Ritter <dsr@randomstring.org> - 2022-05-18 14:50 +0200
      Re: Disable connections to Internet without user's consent Lee <ler762@gmail.com> - 2022-05-18 20:00 +0200

#248309 — Disable connections to Internet without user's consent

FromAndrea Monaco <andrea.monaco@autistici.org>
Date2022-05-17 23:20 +0200
SubjectDisable connections to Internet without user's consent
Message-ID<EocLL-g96j-9@gated-at.bofh.it>
I wonder all the ways a standard installation and configuration connects
to the Internet without the user's consent, and how to disable it.

I can think of the automatic check for updates and the automatic
security updates.  Any other?  Is there a manual page that lists all of
them?



Thanks,

Andrea Monaco

[toc] | [next] | [standalone]


#248310

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-18 00:40 +0200
Message-ID<Eoe1b-g9OS-7@gated-at.bofh.it>
In reply to#248309

[Multipart message — attachments visible in raw view] — view raw

Unless you enable unattended upgrades explicitly (
https://wiki.debian.org/UnattendedUpgrades) Debian wouldn't download them
automatically.
Some tools may send multicast requests (I think Avahi does:
https://wiki.debian.org/Avahi)

You can use `tcmpdump` to check all your Internet traffic, and then use
`iptables` (or `nftables`) to disable unwanted traffic or simply uninstall
software that does it.

Windows does a lot of things under the hood. Linux doesn't.


On Wed, May 18, 2022 at 12:15 AM Andrea Monaco <andrea.monaco@autistici.org>
wrote:

>
> I wonder all the ways a standard installation and configuration connects
> to the Internet without the user's consent, and how to disable it.
>
> I can think of the automatic check for updates and the automatic
> security updates.  Any other?  Is there a manual page that lists all of
> them?
>
>
>
> Thanks,
>
> Andrea Monaco
>
>

[toc] | [prev] | [next] | [standalone]


#248311

FromDan Ritter <dsr@randomstring.org>
Date2022-05-18 01:00 +0200
Message-ID<Eoekx-g9Vs-1@gated-at.bofh.it>
In reply to#248309
Andrea Monaco wrote: 
> 
> I wonder all the ways a standard installation and configuration connects
> to the Internet without the user's consent, and how to disable it.
> 
> I can think of the automatic check for updates and the automatic
> security updates.  Any other?  Is there a manual page that lists all of
> them?

Neither one of those is automatic. Someone with root privileges
needs to install a package like apticron to get that.

I believe, but have not confirmed: if you install a base Debian
stable system, no extra packages, it will not initiate any
connection without user action.

An interface configured to use DHCP would ask for a new one on
lease expiration.


-dsr-

[toc] | [prev] | [next] | [standalone]


#248313

FromCindy Sue Causey <butterflybytes@gmail.com>
Date2022-05-18 05:50 +0200
Message-ID<EoiRb-gdhY-1@gated-at.bofh.it>
In reply to#248311
On 5/17/22, Dan Ritter <dsr@randomstring.org> wrote:
> Andrea Monaco wrote:
>>
>> I wonder all the ways a standard installation and configuration connects
>> to the Internet without the user's consent, and how to disable it.
>>
>> I can think of the automatic check for updates and the automatic
>> security updates.  Any other?  Is there a manual page that lists all of
>> them?
>
> Neither one of those is automatic. Someone with root privileges
> needs to install a package like apticron to get that.
>
> I believe, but have not confirmed: if you install a base Debian
> stable system, no extra packages, it will not initiate any
> connection without user action.
>
> An interface configured to use DHCP would ask for a new one on
> lease expiration.


What about popularity-contest? Regardless of whether it fits in here,
am hoping it maybe triggers thoughts of other packages that quietly
phone home.

As fast as I typed that, I remembered something I experienced a number
of years ago. Certain screensavers used to pull from websites without
my initial knowledge. I don't know how I eventually tripped over the
fact that they did, but it was a momentarily frightening discovery. It
was one of those times that TRUST in Debian Developers' thorough
testing of packages came consciously to mind.

Upon still more reflection, I was on dialup at the time. Maybe I was
offline, and the screensaver some error message that it couldn't
connect to the website.. or it just flat out failed.. or something.
Very odd, scary moment in all this. That TRUST kept things
copacetic... :)

Cindy :)
-- 
Talking Rock, Pickens County, Georgia, USA
* runs with birdseed *

[toc] | [prev] | [next] | [standalone]


#248314

From<tomas@tuxteam.de>
Date2022-05-18 06:30 +0200
Message-ID<EojtT-gdPZ-1@gated-at.bofh.it>
In reply to#248313

[Multipart message — attachments visible in raw view] — view raw

On Tue, May 17, 2022 at 11:39:44PM -0400, Cindy Sue Causey wrote:

[...]

> What about popularity-contest? Regardless of whether it fits in here,
> am hoping it maybe triggers thoughts of other packages that quietly
> phone home.

It is optional, so you'd have to install it explicitly.

Cheers
-- 
tomás

[toc] | [prev] | [next] | [standalone]


#248321

FromDan Ritter <dsr@randomstring.org>
Date2022-05-18 14:50 +0200
Message-ID<EorhM-giID-3@gated-at.bofh.it>
In reply to#248313
Cindy Sue Causey wrote: 
> What about popularity-contest? Regardless of whether it fits in here,
> am hoping it maybe triggers thoughts of other packages that quietly
> phone home.

popcon defaults to off; you have to opt-in.

> As fast as I typed that, I remembered something I experienced a number
> of years ago. Certain screensavers used to pull from websites without
> my initial knowledge. I don't know how I eventually tripped over the
> fact that they did, but it was a momentarily frightening discovery. It
> was one of those times that TRUST in Debian Developers' thorough
> testing of packages came consciously to mind.

There are screensaver modules that pull quotes from remote
sites. They aren't a default, though.

firefox-esr is a prime candidate, but only when it's running.

-dsr-

[toc] | [prev] | [next] | [standalone]


#248323

FromLee <ler762@gmail.com>
Date2022-05-18 20:00 +0200
Message-ID<Eow7L-glCI-3@gated-at.bofh.it>
In reply to#248311
On 5/17/22, Dan Ritter <dsr@randomstring.org> wrote:
> Andrea Monaco wrote:
>>
>> I wonder all the ways a standard installation and configuration connects
>> to the Internet without the user's consent, and how to disable it.
>>
>> I can think of the automatic check for updates and the automatic
>> security updates.  Any other?  Is there a manual page that lists all of
>> them?
>
> Neither one of those is automatic. Someone with root privileges
> needs to install a package like apticron to get that.
>
> I believe, but have not confirmed: if you install a base Debian
> stable system, no extra packages, it will not initiate any
> connection without user action.

Off the top of my head, NTP and DNS lookups for the NTP servers if nothing else.

I don't know what all apt-daily.timer does aside from creating lots of
log msgs, but "daily download activities" doesn't sound like something
I want.  Not that it means all that much, but I haven't noticed any
problems after turning it off:
$ sudo systemctl status apt-daily.timer
● apt-daily.timer - Daily apt download activities
     Loaded: loaded (/lib/systemd/system/apt-daily.timer; disabled;
vendor preset: enabled)
     Active: inactive (dead)
    Trigger: n/a
   Triggers: ● apt-daily.service

Regards,
Lee

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web