3 ms·
The question is then: is this isolation even useful? There are a lot of attacks that still exist when a program runs in userspace and that are not inherent to G
by tleb_ 6y ago
The question is then: is this isolation even useful? There are a lot of attacks that still exist when a program runs in userspace and that are not inherent to GUI programs. Example: creating an executable named sudo somewhere in a directory that is in your ~ and PATH.
- kuschku 6y agoSure, but if you’re under X11, then a flatpak or any other jailed application can still trivially elevate itself to root. Jailing applications only has a meaningful benefit whatsoever under wayland, as a flatpak without bind-home under wayland is actually properly sandboxed. Still a rare case, but at least it’s possible and getting even somewhat common.
- PurpleFoxy 6y agoWayland is only one piece in the security puzzle. Flatpak and SELinux are the other pieces. Under X there is no point sandboxing a GUI app since X provides an escape.