10 ms·
I mean, it looks cool and all, but I'm not quite sure I get it. Let's say I download a GUI application I kinda trust, but not fully. For example streamlink-twit
by LockAndLol 6y ago
I mean, it looks cool and all, but I'm not quite sure I get it. Let's say I download a GUI application I kinda trust, but not fully. For example streamlink-twitch-gui [1]. It's a crossplatform GUI for Twitch that uses electron.
Let's say the binary downloaded has 2 exploits:
1. It zips all dot files in the user's home and sends them to a server.
2. It send the X clipboard to a server.
Does firejail protect against either attack? If so, how?
For apps like these, I would have a script that creates a new user, copies the app into $newUserHome, starts Xephr [2] a my main user, starts the app as $newUser with DISPLAY=:$xephrDisplay. I'm no security expert, but those 2 issues seem solved that way. Does firejail practically do something similar but with kernel magic?
[1]: https://github.com/streamlink/streamlink-twitch-gui https://github.com/streamlink/streamlink-twitch-gui
[2]: https://en.wikipedia.org/wiki/Xephyr https://en.wikipedia.org/wiki/Xephyr
- pythux 6y agoI am far from being an expert but I think that: 1. Is solved by most profiles which will only give access to files required by the given app so it would not get access to all content of the home folder. And even better (although not default behavior), is to use --private to isolate each app into its own fake home folder. 2. Is also not default but seems to be possible according to official wiki: https://firejail.wordpress.com/documentation-2/x11-guide/ https://firejail.wordpress.com/documentation-2/x11-guide/
- LockAndLol 6y agoVery interesting! Thank you. I might start using firejail now.