3 ms·
I'm starting to think something like flatpak or snap is necessary, but in a more sandboxed way, to enforce on the user level that certain apps won't have access
by chris_mc 8y ago
I'm starting to think something like flatpak or snap is necessary, but in a more sandboxed way, to enforce on the user level that certain apps won't have access to certain files. I would like to see options to fully sandbox an app (has it's own separate permissions for certain documents) or not sandbox it at all (for things we trust implicitly that need that access).
- danShumway 8y agoflatpak permissions + Wayland are (imo) some of the best things happening on Linux right now. You could always kind of do the same stuff with containers and custom wrappers around each program, but it's really cumbersome. I want this to be the normal. Right now, it's basically a free for all -- record the screen, send network requests, fingerprint hardware, scan for files, examine other processes. The default, out-of-the-box security settings for most distributions are unacceptable. I'm really excited to see that sandboxing on native is starting to move in the same direction as the web; I'm hoping that within the next year or two we start to see dramatic improvement here.