Isn't that more-or-less the same as setting up iptables to block everything but IPs in your local subnet?
It may be the safest solution at the moment, but it would still be nice to kill the updating process at the application layer so we don't have to resort to network-layer blocks.
|