3 ms·
This issue goes beyond MacOS too. The traditional model of allowing any process to read and write anything created by the same user, send IPC messages (unix soc
by muricula 6y ago
This issue goes beyond MacOS too. The traditional model of allowing any process to read and write anything created by the same user, send IPC messages (unix sockets, mach ports, window messages etc.) to most processes, and execute any subprocess has serious security and privacy implications. iOS, Android, and to a lesser extent ChromeOS offer a different, more intuitive, security model, but one which is difficult to retrofit to traditional OSs.
Attempts to retrofit a sandbox to older OSs are full of holes, and it's interesting to see how different ecosystems attempt to do this, with containers, AppArmor, the seatbelt sandbox, and other things brewing in Redmond.
- the_duke 6y agoSnap / Flatpack are probably the most promising attempts in this area. Personally I think it will be incredibly hard and tedious to morph the Linux desktop into a properly sandboxed environment, exactly because you are fighting long established conventions and norms in just about every aspect of development and application usage. Fuchsia (Googles new OS) might prove very interesting in this regard.
- jakear 6y agoI find most of the time when I’m installing snaps I need to use —dangerous. I’m not sure what exactly it does, but my guess is that it renders whatever security snaps are supposed to provide moot.
- alasdair_ 6y agoYou could look at something like Qubes OS which tries to sandbox things as much as possible via virtualization. It’s pretty cumbersome to use however. https://en.m.wikipedia.org/wiki/Qubes_OS https://en.m.wikipedia.org/wiki/Qubes_OS
- kchr 6y agoNot cumbersome at all if you adhere to the core principles and think through how you actually use your computer. Contrary to popular belief, you do not have to run every application in its own (VM). You can run any number of apps in a single VM, so the principle is that you define what applications (use cases) can and should be isolated from each other and use multiple VMs to implement that segmentation between (groups of) apps. For example, you can have one VM for all your work apps and another for the remaining use cases.
- pjmlp 6y agoRegarding the things brewing in Redmond I am looking forward to how Windows 10X will turn out to be.
- saagarjha 6y agoWhat’s brewing in Redmond, and how is Microsoft going to get old legacy apps to play along with it?
- pjmlp 6y agoWindows 10X has sandboxes for everything, there are no exceptions. This is a path that started when people voted against UWP, then they went the other way around, bringing the UWP sandbox model to Win32. First there was Desktop Bridge where Win32 apps would run sandboxed, but with full trust. Then came the MSIX package format that would apply a bit more of sandboxing and less trust than Desktop Bridge introduced. Now with Windows 10X they are building on top of the picoprocesses that came from Project Drawbridge and were used in WSL 1 to wrap each Win32 application into its own little world. It is only a matter of time until this expands to other SKUs. As for the legacy applications, I guess just like with those stuck in Windows XP, either adopt the future or stay behind.
- badsectoracula 6y ago> As for the legacy applications, I guess just like with those stuck in Windows XP, either adopt the future or stay behind. I have a very strong feeling that it will be Windows 10X that will be "left behind". The entire point of using Windows nowadays is to be able to use existing Windows applications.
- pjmlp 6y agoI don't think so, given I have been following the evolution of Windows sandbox model for a decade now. Every time there were any issues, it was dealt with one step back two forward tactic.