5 ms·
+1 for firejail [1]. There's a guide on how to do this for firefox [2] (see the network setup section), but this can be used with other applications as well. [
by cameronperot 6y ago
+1 for firejail [1]. There's a guide on how to do this for firefox [2] (see the network setup section), but this can be used with other applications as well.
[1] https://firejail.wordpress.com/ https://firejail.wordpress.com/
[2] https://firejail.wordpress.com/documentation-2/firefox-guide/ https://firejail.wordpress.com/documentation-2/firefox-guide...
- anderspitman 6y agoNote that the further I went down the sandboxing rabbit-hole, the more questions it raised about whether it's more or actually less secure. The main problem is that in order to work, these tools often use a setuid binary, which actually has more permissions than most users. So in theory if a sandboxed app finds an exploit in the sandboxing program (like firejail) that you're running inside, you could actually be worse off than it breaking out of whatever program you're sandboxing in the first place. I think in this case though where you're more concerned about the very real problem of websites accessing localhost, it probably outweighs the maybe of a firejail exploit.
- Thriptic 6y agoIt's also possible to run a web browser in a docker container which can be interacted with on the host OS. This avoids the permissions issues with solutions like firejail: https://blog.jessfraz.com/post/docker-containers-on-the-desktop/ https://blog.jessfraz.com/post/docker-containers-on-the-desk...
- willglynn 6y ago`docker` implies access to the Docker daemon, which is not an improvement over the setuid binaries anderspitman found distasteful. https://docs.docker.com/engine/security/security/#docker-daemon-attack-surface https://docs.docker.com/engine/security/security/#docker-dae...
- lxdquestion 6y agoGenuine question, would LXD be any better? I'm not an expert in containerization but I find it really interesting. There are some blogs that talk about how to do this: https://blog.simos.info/how-to-easily-run-graphics-accelerated-gui-apps-in-lxd-containers-on-your-ubuntu-desktop/ https://blog.simos.info/how-to-easily-run-graphics-accelerat...
- sadfklsjlkjwt 6y agoIf it runs in the same Xwindows session no.
- deleted 6y ago[deleted]
- folmar 6y agoIf your docker is in fact podman your rootless might be attainable.
- sadfklsjlkjwt 6y agoPlease don't suggest using Docker to sandbox a GUI app.
- xorcist 6y agoThat's not a good idea. The attack surface of docker is enormous compared to firejail.
- cameronperot 6y agoInteresting point, I hadn't made it that far down the rabbit hole. I agree that it's not a complete solution, and possible risks of exploiting the sandbox itself should be taken into account on a case-by-case basis.
- segfaultbuserr 6y ago> these tools often use a setuid binary, which actually has more permissions than most users. These tools often drop privileges as soon as the program is executed, in firejail, there's also an option to disalble root entirely within a namespace.