{"id":281,"date":"2010-01-19T11:29:47","date_gmt":"2010-01-19T19:29:47","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=281"},"modified":"2010-01-19T11:29:47","modified_gmt":"2010-01-19T19:29:47","slug":"using-huludesktop-on-mythtv","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2010\/01\/19\/using-huludesktop-on-mythtv\/","title":{"rendered":"Using huludesktop on MythTV"},"content":{"rendered":"<p>Based on a friend&#8217;s recommendation, I decided I would install <a href=\"http:\/\/www.hulu.com\/labs\/hulu-desktop-linux\">Hulu Desktop<\/a> for my MythTV system.<\/p>\n<p>The <a href=\"http:\/\/www.mythtv.org\/wiki\/Hulu_Desktop_Integration\">MythTV wiki instructions<\/a> were very good.  However, I didn&#8217;t like that it was a closed-source binary doing network traffic. (While &#8220;system&#8221; doesn&#8217;t show up in &#8220;<code>readelf -r<\/code>&#8221; output, that doesn&#8217;t mean it isn&#8217;t doing direct syscalls, or manually finding the &#8220;system&#8221; offset in the libc library, or is vulnerable to overflows, and on and on.)  So, to put my mind at ease, I decided to confine it in an AppArmor profile:<\/p>\n<blockquote><p>#include &lt;tunables\/global&gt;<\/p>\n<p>\/usr\/bin\/huludesktop {<br \/>\n  #include &lt;abstractions\/gnome&gt;<br \/>\n  #include &lt;abstractions\/audio&gt;<br \/>\n  #include &lt;abstractions\/nameservice&gt;<\/p>\n<p>  \/etc\/huludesktop\/** r,<br \/>\n  @{HOME}\/.huludesktop rwkl,<br \/>\n  @{HOME}\/.local\/share\/.huludesktop.data rwkl,<br \/>\n  @{HOME}\/.macromedia\/Flash_Player\/macromedia.com\/support\/flashplayer\/sys\/*.hulu.com\/** r,<br \/>\n  @{HOME}\/.macromedia\/Flash_Player\/#SharedObjects\/ r,<br \/>\n  @{HOME}\/.macromedia\/Flash_Player\/#SharedObjects\/*\/*.hulu.com\/ rw,<br \/>\n  @{HOME}\/.macromedia\/Flash_Player\/#SharedObjects\/*\/*.hulu.com\/** rwkl,<\/p>\n<p>  # MythTV is already managing the screensaver<br \/>\n  deny \/usr\/bin\/xdg-screensaver x,<br \/>\n}\n<\/p><\/blockquote>\n<p>Additionally, I disabled its <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/Roadmap\/ExecutableStacks\">executable stack<\/a>, which seems to serve no purpose:<br \/>\n<code>$ <strong>sudo execstack -c \/usr\/bin\/huludesktop<\/strong><\/code><\/p>\n<p style='text-align:left'>&copy; 2010, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Based on a friend&#8217;s recommendation, I decided I would install Hulu Desktop for my MythTV system. The MythTV wiki instructions were very good. However, I didn&#8217;t like that it was a closed-source binary doing network traffic. (While &#8220;system&#8221; doesn&#8217;t show up in &#8220;readelf -r&#8221; output, that doesn&#8217;t mean it isn&#8217;t doing direct syscalls, or manually [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,6,14],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/281"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=281"}],"version-history":[{"count":10,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/281\/revisions"}],"predecessor-version":[{"id":291,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/281\/revisions\/291"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}