4 ms·
That would be true if someone refused to use any form of sandboxing, however there are multiple sandboxing solutions available that the "door" works in combinat
by cycloptic 6y ago
That would be true if someone refused to use any form of sandboxing, however there are multiple sandboxing solutions available that the "door" works in combination with. That is the only real way to make this kind of security work on an ordinary Linux distribution, the approach used by Android where a new user is created for each application is not really feasible.
There are also ways to sandbox X11, it's a bit harder to do, but you do have some options on how you'd like to do things.