4 ms·
The technological ludditism is exhausting. We know some things are *objectively* better than the status quo. With attack surface as big as a modern browser or
by higerordermap 6y ago
The technological ludditism is exhausting.
We know some things are *objectively* better than the status quo. With attack surface as big as a modern browser or media player, not having sandboxing would be a mistake.
Just the people who are stuck to 1970's way of doing things and fear new things oppose sandboxing.
- Jouvence 6y agoSandboxing is fine, but it sounds like Snaps/Flatpaks don't actually do it because that would be too hard - so what's the point? I get that some packages do actually have sandboxing, but unless it is mandatory and enforced I feel like I'm better off avoiding the ecosystem entirely and dealing with app isolation myself, using containers or VMs.
- viraptor 6y agoSnap/Flatpak are not doing it because that's not the layer which "does it". They provide the framework which allows since sandboxing today and will provide better sandboxing tomorrow. It's up to the app distributors to support it or not. We won't get full support immediately either. It may be too hard today. But that's less "Flatpak is a security nightmare" and more "we're not using the features we have very well yet". I feel like some people expected 100% targeted profile for each app or will declare sandboxing a failure. This stuff will take years.
- als0 6y agoOn average, I've found Snaps to be better sandboxed. But there are plenty of things to dislike about Snap e.g. not respecting XDG base directory spec, persistent daemon running as root, requiring sudo, unable to control when it decides to autoupdate, coarse grain "connection" system ...and more. A lot of obvious design mistakes that don't get fixed for one reason or another.
- blacksmith_tb 6y agoWell, they are also marketed as a way of isolating dependencies, which they do actually manage to some degree. So they could be weak security-wise without being completely pointless?
- still_grokking 6y ago> The technological ludditism is exhausting. That sounds funny given the facts about Flatpak.
- benibela 6y agoI have run the browser on a separate user account for years
- ohazi 6y agoI don't understand why this isn't more popular. This has been the sandboxing method or choice since the 70s. Filesystem permissions were designed around users and groups, and now everybody's trying to bolt on intra-user access control lists and wondering why the experience sucks so much. Create a `browser` user. Add yourself to the `browser` group. Maybe give `browser` read access to an area in your docs folder for convenience. Modify your browser launch script. Done.
- benibela 6y agoI have a few problems. In the default settings other users could not access the X server. I forgot how that is changed. I changed it once and now just copy the config Biggest is getting the sound to work. Pulseaudio in system mode should do it. Although it is not recommended to use. And now my headphones do not work reliable anymore. Not sure if it is caused by system mode or by another setting. And sharing files. Good that the browser cannot change my files, but it works both ways. My normal user cannot change the browser files, sometimes not even access the downloads.
- gspr 6y ago> We know some things are objectively better than the status quo. With attack surface as big as a modern browser or media player, not having sandboxing would be a mistake. Absolutely. That's why the comment that makes you characterize me as a luddite explicitly referred to the "sandbox everything wave". Sandboxing has its place. Sandboxing everything (i.e. the "Flatpak way") is what I'm commenting on.
- danShumway 6y agoI think that GP's point still stands. Application security on most native platforms right now is a disaster. But application security on Linux is a dumpster fire. Yes, there are ways to do it better with SELinux, yes there are ways to isolate apps, but they're overcomplicated, inaccessible, and the end result is that most consumers don't use them. Flatpak, for all of its many faults (and there are a lot of them), is still a strict improvement over the current security model running on most desktop Linux computers. Sandboxing native applications (even partially sandboxing them) is objectively better than the status quo. It is embarrassing that the Linux community is still having this debate. It is exhausting, it feels like the community has to be dragged kicking and screaming away from a 20-year old security model that every other platform has moved on from.
- candiodari 6y agoSo you think that disallowing access to word processor files to zip and unzip, or backup utilities, or ... is a perfectly reasonable way of doing things? Because that's what we do on the web. Every app only has access to it's own files and 10 or so standard clipboard formats (and ONLY through the clipboard).
- danShumway 6y agoHaving a portal that dictates file access would be a perfectly reasonable way of doing things, and that's the direction that Flatpak security is at least starting to move in. There are security models that allow sharing files that don't give direct access to the entire filesystem. A word processor might need access to my Documents folder, but I might choose not to give it access to anything outside of that folder. Or I might choose to tell it it's been given access to a Documents folder, but really it has access to a VFS mount that is a composite of several folders inside of Documents including some shared folders outside of Documents. This kind of "portal" idea is incidentally also what browser manufacturers are considering as they start to explore offering native file access[0] (although this is obviously an area that in browsers needs to be approached with a lot of caution). I don't think Google's proposal is the best way to handle this, I think it could be better. But it's still better than what's happening on desktops with native apps. [0]: https://web.dev/file-system-access/ https://web.dev/file-system-access/
- kabdib 6y agoI dislike sandboxes that - have complicated permissions that users misunderstand or can be tricked into misconfiguring through inattention, misleading user interface or fatigue - aren't actually sandboxes because the isolation they claim isn't actually achieved (I usually call these "security holes") - are used to artificially force markets (e.g., Microsoft's UWP) Other than that, they're great. Signed, cranky, pre-morning-coffee programmer speaking ex cathedra from the 1970s
- higerordermap 6y agoI think this is a valid criticism from flatpak / snap. But they are step in right direction about sandboxing (on the other hand bloat and developer trust are main problems abou these platforms for me).
- fao_ 6y agoExcept Multics, which predates UNIX, already had a lot of these features but better. https://www.acsac.org/2002/papers/classic-multics.pdf https://www.acsac.org/2002/papers/classic-multics.pdf I don't understand how you can honestly, truly say it's "technological ludditism" when it's clear that nobody in this thread is opposing the features that Flatpack and Snap claim to have, which in many forms predate UNIX and predate Flatpack/Snap -- they are just opposing the half-baked implementation that Flatpack/Snap have created.
- mdoms 6y agoCalling opinions you disagree with "exhausting" is exhausting. And obnoxious.