3 ms·
Sandboxing is a huge issue that plagues desktop operating systems. And sadly is it only one piece of the puzzle. Android for example additionally has detailed S
by SubzeroCarnage 5y ago
Sandboxing is a huge issue that plagues desktop operating systems. And sadly is it only one piece of the puzzle.
Android for example additionally has detailed SELinux policies and extensive compile time hardening.
You can sandbox the majority of your apps on desktop Linux today with two simple commands:
- sudo apt/dnf install firejail
- sudo firecfg
Project: https://github.com/netblue30/firejail https://github.com/netblue30/firejail
Intro Video: https://www.youtube.com/watch?v=N-Mso2bSr3o https://www.youtube.com/watch?v=N-Mso2bSr3o
Disclosure, I am a contributor to firejail.
Also if you are already using flatpaks, you can install flatseal to easily point and click which permissions you want:
https://www.flathub.org/apps/details/com.github.tchx84.Flatseal https://www.flathub.org/apps/details/com.github.tchx84.Flats...
Lastly you can sandbox your systemd daemons:
https://www.freedesktop.org/software/systemd/man/systemd.exec.html#Sandboxing https://www.freedesktop.org/software/systemd/man/systemd.exe...
Have fun!
- snickerer 5y agoFirejail is the solution to the author's concerns. I only would suggest a whitelist based approach instead of a blacklist approach.
- SubzeroCarnage 5y agoA whitelist/allowlist approach doesn't work for all programs, see this discussion about it: https://github.com/netblue30/firejail/issues/2070 https://github.com/netblue30/firejail/issues/2070
- prakis 5y agoThis is the solution we need in all OS's. Excellent work.