I want to prevent some apps from going to network, so I've created a no-internet group:
sudo groupadd -g 9876 no-internet
and created a script
sudo gedit /usr/bin/ni
#!/bin/bash
sg no-internet "$1"
And added an iptable rule
#!/bin/bash
iptables -A OUTPUT -m owner --gid-owner no-internet -j DROP
Now ni my_command
should run an app in a restricted mode. However, I am getting sg: failed to crypt password with previous salt: Invalid argument
How can I run an app as 'no-internet group`, without limiting my own access to LAN/WAN?
I've checked this question (claiming that requirements are contradictory)
How to switch a group without asking for a password?
But is it really so?
ni
inno-internet
group ? – Archemar Mar 25 '18 at 13:47ni untrusted-app
in order to prevent this app from talking to internet. I don't want to block my own access to internet though. – sixtytrees Mar 25 '18 at 22:26