9 ms·
I am far from expert in this but I am not sure I would be comfortable automatically configuring all my apps to run through Firejail using firecfg (if only becau
by pythux 6y ago
I am far from expert in this but I am not sure I would be comfortable automatically configuring all my apps to run through Firejail using firecfg (if only because in case of breakage it would be harder to understand where it is coming from).
In my workflow, I keep things mostly manual and configure each app I want to sandbox explicitly by creating a shortcut (usually I create a "launcher" in /usr/local/bin so that it takes priority over whatever is in /usr/bin). Here is the one I have for Firefox as an example in "/usr/local/bin/firefox":
firejail --profile=/etc/firejail/firefox.profile --private=~/.sandboxes/firefox/ /usr/bin/firefox --no-remote $@
In terms of risks, are you mostly concerned about security risks? Or breakage?
- Vinnl 6y agoThanks. I'm concerned about both, but I suppose I consider breakage to be the biggest risk for something of which I hardly know what it does. Your approach sounds viable though, so I might look into setting something similar up for myself as well. Thanks for sharing.