5 ms·
It is very disappointing that in 2019 we still have to rely on trusting a software vendor or reading the app souce code if it is available. That would be great
by duchenne 7y ago
It is very disappointing that in 2019 we still have to rely on trusting a software vendor or reading the app souce code if it is available. That would be great to we have an OS-level system to give fine-grained permissions and restrictions to desktop apps, like on lineageOS?
- Godel_unicode 7y agoHow would fine grain permissions solve the problem of software doing something fishy with the code you give it access to?
- brassattax 7y agoWhite list for network access?
- abstract7 7y agoDisabling unsafe and unnecessary sys calls in containers (not Docker) and forcing apps to communicate via API with capabilities management would let you do this now, I think. In fact, sandstorm.io is said to do all this. And it's open-source. I never used it, except the demo. And I'm not sure if its PowerBox (manages capabilities) is fully implemented.
- xorcist 7y ago> like on lineageOS? Android/LineageOS is Linux. Just type adduser and sudo, it's not too bad. You'll probably find, however, that it might not be all you were looking for. It can still steal your source code and credentials, which might have been what you were worried about. You will also miss out on your editor, compiler, zip utilities, and whatever else that's not included in your git client. Anything useful would probably look more like privileges (where opening a file can be ok but a network socket forbidden). There's been a ton of research in this area and some very mature systems such as SELinux.