3 ms·
firejail is also super super insecure: https://www.cvedetails.com/vulnerability-list/vendor_id-16191/Firejail-Project.html https://www.cvedetails.com/vulnerabil
by Hello71 5y ago
firejail is also super super insecure: https://www.cvedetails.com/vulnerability-list/vendor_id-16191/Firejail-Project.html https://www.cvedetails.com/vulnerability-list/vendor_id-1619.... the vast majority of these are trivial bypasses, like "what happens if i mount over /etc/shadow". everyone that can access firejail has a one-inch wall between them and full root access. by default, installing firejail gives everyone on the system access, so installing firejail is basically the closest thing to making everybody root unless you manually configure it to only allow certain users access.
- tome 5y agoMaybe this is a stupid question, but what's the point of an application that's intended to make your system more secure but actually makes it less secure? Do the firejail maintainers not realise? Or do they not agree that it's insecure? Or what? I can't reconcile these CVEs with anyone ever wanting to use firejail ever.
- tedunangst 5y agoI think the assumption is that the user, outside the jail, is already trusted. (You're running this on your personal laptop, etc.) Therefore it "doesn't matter" if they can abuse firejail to get root, they already have that ability. (Not an endorsement.)
- tome 5y agoI see, so the system gains strength against untrusted code (Zoom client, Javascript in the browser, etc.) at the cost of losing strength against the local user. If so then the benefit is really balanced on a knife edge! If the sandboxing is not implemented, or fails, then the untrusted code can run with root privileges!
- folmar 5y agoFor typical single user with DE it's not that much tipped-once you can write to real $HOME you easily go to have root through replacing sudo password dialog or similar. Most desktop-targeted distributions drift towards the console user having a lot of privileges already (but not directly root access).
- goodpoint 5y agoThis is the case for most desktop users. All the valuable data is in the user account. If the user account is compromised all valuable data (password, keys) is gone. Gaining root is hardly useful to an attacker.
- johnisgood 5y agoFirejail offers private home (i.e. not your actual), and disallows running executables within, etc.
- mid-kid 5y agoPointing to CVE lists is misleading. Not all programs have enough eyes on them to even get CVEs, and many programs don't file CVEs for security fixes. Bubblewrap has shared more than one CVE in this list but it was never reported for that.
- WhyNotHugo 5y agoI found a way out of the filesystem sandbox by accident after like 3 days. The devs patched it up super quickly, but I'm still a bit skeptical. It's probably still better than nothing...