Comment Re:Wrong paradigm here (Score 1) 187
This is changing though. If you run a distribution with SELinux enabled, many applications and daemons are likely to be blocked from making outbound connections. Changing the rules is somewhat difficult though; distributions generally assume that the user does not have a clue when asked whether frobnitzd should be allowed to connect to Slashdot, so there is no GUI for asking the user.
AppArmor can do it too, and the configuration is perhaps a bit easier. I have no idea how much Ubuntu restricts by default.