Skip to content
  • intrigeri's avatar
    Firewall: reject packets sent on the LAN to the NetBIOS name service. · b1099c14
    intrigeri authored
    This is about https://en.wikipedia.org/wiki/NetBIOS#Name_service, that allows
    registering and looking up names on a LAN. Best case, it gives a very nice UX
    for service discovery on the LAN (in this case: connecting to a local Gobby
    server), which can be super cool for teams working from a single location.
    Worst case, it leaks things like the hostname on the LAN.
    
    We've never made any serious attempt at supporting zeroconf and
    friends (although Tails Server might be a game changer), so for now let's
    explicitly drop these packets. The only practical problem I can think of is that
    it might cause is making discovery of some network printers harder. That's not
    worth the risk of announcing our hostname, or worse, though.
    
    Closes: #11944
    b1099c14