6 ms·
Sandboxie-Plus – a fork of Sandboxie with improved functionality
- realpanzer 6y agoYou can follow the news about it here: https://www.wilderssecurity.com/threads/sandboxie-plus-sbie-fork.427755/ https://www.wilderssecurity.com/threads/sandboxie-plus-sbie-...
- imiric 6y agoAfter an uncertain period for this project, I'm very happy Sophos decided to open source it and that the community is continuing its development. It's absolutely essential if you're running any untrusted applications on Windows, allowing an extensive level of control over the resources the app is allowed to access (registry, filesystem, network, etc.). It's similar to containers on Linux in that sense, it has little to no overhead (sandboxing games works great in most cases), but in an even more user-friendly package than something like Docker. Highly recommended.
- algo_trader 6y agoa. sandboxie[plus] is fantastic, both as a concept and in actual use. b. What is the status of docker-on-windows? is it stable-but-slow or simply not ready yet ? c. Why didnt Sandboxie become a multi-million-$ project? It was years ahead of docker, and there is a great need for it on Windows than Linux IMHO.
- ComodoHacker 6y agoc. Probably because Windows has gained native sandboxing mechanisms to cover majority of common use cases. I wonder if this new incarnation of Sandboxie uses any of them.
- runxel 6y agoBut only in the Pro version?! Windows 10 Home doesn't have it.
- moreorless 6y agoThere is a workaround: https://geekermag.com/enable-windows-sandbox-in-windows-10-home/ https://geekermag.com/enable-windows-sandbox-in-windows-10-h...
- oscargrouch 6y agoI think is weird that Microsoft uses security as a feature for customers who pay more. I mean, security, if universal in their platform, would only give more prestige to the Windows brand, so why to let some of their users unprotected, specially when lack of security features, virus, etc.. have hurt so much the Windows brand? They should give other kind of features and apps instead. Never negotiate security, and made it universal, giving more strength to their image. Think of it, in the end you will be paying to be protected from the insecurity that is only there because of the flaws in their platform. Its like a mob rising the crime levels on a neighborhood and at the same time asking to be payed to grant you security for the troubles people are only having because they are creating those same troubles in the first place (even if/when indirectly).
- runxel 6y agoSo much yes! I never understood why you would have to pay for security... "Oh look, our software is inherently insecure, but if you pay more, you can get a mitigation." It truly gives no good light on whatever you sell.
- R0b0t1 6y agoWhich features?
- staticassertion 6y agoDoes it provide copy on write semantics? I wasn't aware of that being the case.
- password4321 6y agoIt probably was part of the basis of a multi-million-$ project. Sandboxie was a big part of the original technology used by Invincea which was later aquired by Sophos. https://en.wikipedia.org/wiki/Invincea https://en.wikipedia.org/wiki/Invincea
- GordonS 6y agoDocker Desktop has provided docker on Windows desktop editions for some years now. It's very stable and fast too (I use it basically every day). If you're asking specifically about Windows containers though, I've never used them (few do, I think).
- dannyw 6y ago> The SbieDrv.sys driver must be signed, and since the appropriate certificates are prohibitively expensive, I head to use a leaked code signing certificate I found laying around the Internets. This means some anti malware applications wrongfully flag it as potentially dangerous or a virus. Finding leaked but operational EV code singing certs online should not be a thing ...
- corty 6y agoJust emphasizes what is common knowledge anyways: code signing is security circus in windows, it's just an entry tax really.
- R0b0t1 6y agoTo anyone who doubts this: while there is strict enforcement for kernel code just having a signature on binaries or scripts silences errors.
- GordonS 6y agoA valid signature. That means the signature must chain to a trusted root CA, and the signing must have taken place within the signing certificate's validity period. If the certificate has expired at the time the user executes the binary, a counter-signature from a trusted timestamping service must also be present, to prove the binary was indeed signed within the certificate's validity period. This seems fairly sane to me, and and allows doing things in software like trusting particular publishers.
- G4E 6y agoI used Sandboxie 10 years ago, when I was still using Windows. It is a really neat piece of software. I'm glad it went open-source instead of simply dying because of lack time and/or interest. I had a surprising hard time to find an equivalent for linux. Today firejail fill that void pretty well.
- manjalyc 6y agoSandboxie is one of the few programs that I allow to autostart on my Windows installations. It is an ingenious piece of software with a dead simple yet extremely powerful interface. Glad to see it’s free software/open source instead of just dying a slow death. It’s saved my ass more than once and made my life a lot easier.
- fny 6y agoAny idea if it's possible to do this with macOS and 'nix systems? I've been thinking about giving it a stab myself, and I can't think of any obvious roadblocks.
- nacs 6y agoThere are tons of sandboxing applications for Linux. Also a few solutions like Snap and Flatpak exist on Linux where the applications come pre-sandboxed. For Mac, the official Mac App Store's applications are all sandboxed also.
- pmoriarty 6y ago"There are tons of sandboxing applications for Linux." Which of them are widely used, as easy to use and as feature rich as Sandboxie, and are well maintained?
- oedmarap 6y agoI use Firejail[0] on my Linux machine to achieve the same effect. [0] https://firejail.wordpress.com/ https://firejail.wordpress.com/
- freedomben 6y agoI decommissioned my last Windows about 10 years ago, but Sandboxie was a killer app that I missed sorely. It was ingenius and saved my ass a few times. Much the way people probably feel when iOS started showing clipboard access so you could physically see when apps were doing something invasive? That was the feeling I got constantly with every app and every invasive action when I was using Sandboxie. Truly a gem.
- miles 6y agoSince version 1903, Windows 10 has included a built-in sandbox feature as well: How to Safely Run Software With Windows 10 Sandbox https://www.pcmag.com/how-to/how-to-safely-run-software-with-windows-10-sandbox https://www.pcmag.com/how-to/how-to-safely-run-software-with...
- pmoriarty 6y agoHow does this compare with Sandboxie? Are there any reasons to use one over the other?
- whiw 6y ago1. When you open a win10 sandbox it appears as a fresh install of windows. Only Microsoft Edge is pre-installed. If you like to tweak privacy settings etc then you'll need to re-tweak them every time you start up a win10 sandbox (as they too get forgotten)> 2. Everything gets wiped when you close a win10 sandbox (so installations can't survive beyond a login session). In Sandboxie you appear to get a copy of your existing OS, and the copy is only wiped when you choose to wipe it (so it can survive across login sessions). The win10 sandbox is wiped when you close it, and you have to close it to turn off the PC. 3. Win10 sandbox seems not to like making the camera or microphone available to apps (eg zoom, skype) whereas Sandboxie is happy with making them available. 4. Because of the above, win10 sandbox is probably more secure than sandboxie, but there is no indication of where the sandbox state was stored, so it isn't possible to secure delete it like you can with sandboxie.
- pmoriarty 6y agoThere's a feature that I really like in Sandboxie, which is that it can preserve certain folders from being deleted. I use this feature when I run Firefox in a Sandboxie sandbox while preserving it history and bookmarks. I find it pretty annoying to have those cleared whenever I delete my sandbox, so much prefer to have those saved. It sounds like the win10 sandbox can't do this.
- kasabali 6y ago
- swatkat 6y agoThere's another Sandboxie fork here: https://github.com/sandboxie https://github.com/sandboxie As per this[1] post, it's going to be a continuation of existing Sandboxie without major changes. And, it's going to have signed driver. [1] https://www.wilderssecurity.com/threads/sandboxie-technologies-sbie-open-source.428156/ https://www.wilderssecurity.com/threads/sandboxie-technologi...