okay this is super fucking excellent:
https://obdev.at/products/littlesnitch-linux/index.html
thank you @cR0w for letting me know it exists.
little snitch is fucking awesome. its the de-facto host-level firewall for macs these days and its impressively effective.
to have this for linux?
game changer.


