4 ms·
I firmly believe that isolation is the future of endpoint security and I like experimenting with Mandatory Access Control (MAC) on Linux. Tomoyo is my favorite
by _wldu 4y ago
I firmly believe that isolation is the future of endpoint security and I like experimenting with Mandatory Access Control (MAC) on Linux. Tomoyo is my favorite major MAC/LSM in the Linux kernel.
If you have a newer kernel (5.13 or greater), you may like to experiment with landlock. It's pretty cool and unlike FireJail, no suid required. Here's a landlock wrapper for Firefox:
https://github.com/62726164/misc/blob/main/go/landlock/firefox/main.go https://github.com/62726164/misc/blob/main/go/landlock/firef...
I'd like to learn more about open source/free Windows and MacOS MAC tools. If you know of any, please post about your experience with them.
Edit: This Windows functionality seems similar to seccomp and pledge: https://docs.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_system_call_disable_policy https://docs.microsoft.com/en-us/windows/win32/api/winnt/ns-...
- lewantmontreal 4y agoWow that looks cool. I really want to install apps without entrusting my entire hard drive to them.
- rockdoe 4y agoUnix applications run as a user, so it's not like they have that permission. Looking at that profile, it restricts write access to the home directory to only the Firefox profile and some config files. I guess that makes sense, but you'd have to be aware of it when uploading and downloading stuff (it would only work from a specific designated folder).
- kaba0 4y agoAnd where are all the valuable files stored like family pictures, other browsers’ cache, ssh keys etc.? In the same user’s home dir, so in practice most desktop apps do have uncontrolled access to everything on the harddrive as per the now quite old xkcd comic ( https://xkcd.com/1200/ https://xkcd.com/1200/ ). Ideally, a “shadow” Download folder would be accessible to the process, and its content would be mirrored one-way into the real Downloads folder. Upload should display a file chooser dialog which runs in an entirely different process, and the chosen files should be in effect copied to the process’s file handles list.
- yjftsjthsd-h 4y agoAIUI this is basically how flatpak does it; the file picker is called a "portal" and is indeed how you pass in files that the program couldn't reach by default.
- kaba0 4y agoAnd that is a welcome change. What I dislike about the project is that it want to be a packaging solution as well, and it is simply not a good one at that compared to the new generation one, which is Nix. Linux really shouldn’t copy Mac and Windows on everything.
- _wldu 4y agoThank you! And, yes, I agree. I don't want FireFox or Chrome reading ~/.ssh or ~/.gnupg or any other directories in my home that it has no business reading. Maybe one day we'll have web browsers that don't have any C code. Nothing against C. It's a great systems language, but I'd rather my web browser not use it. Browsing the web is probably the most dangerous thing the average computer user does.
- rockdoe 4y ago>I don't want FireFox or Chrome reading ~/.ssh or ~/.gnupg or any other directories in my home that it has no business reading. Both browsers already do this for the processes that are exposed to the internet. The software shown here additionally does it for the entire browser (with the caveat wrt uploading/downloading that I explained, and maybe some more gotchas that aren't immediately obvious). (You may understand this nuance, but I wanted to point it out, as it's literally what the browser sandboxes do)
- account42 4y ago> Maybe one day we'll have web browsers that don't have any C code. Nothing against C. It's a great systems language, but I'd rather my web browser not use it. Both Firefox and Chrome are primarily written in C++, not C. They do use C libraries though including libc.
- chrisseaton 4y ago> I really want to install apps without entrusting my entire hard drive to them. This is what macOS enforces - apps live within their containers.
- lewantmontreal 4y agoThat sounds interesting. There must be apps that do require full access (like a finder alternative), so I wonder if you can know to trust an app to be isolated just by looking at it.
- notriddle 4y agoApps distributed through the App Store are required to be sandboxed. Apps you install from elsewhere may or may not be. https://developer.apple.com/library/archive/documentation/Security/Conceptual/AppSandboxDesignGuide/AboutAppSandbox/AboutAppSandbox.html https://developer.apple.com/library/archive/documentation/Se...
- kijiki 4y agoflatpak does this on Linux. There is an official-from Mozilla flatpak available for Firefox.
- kiwijamo 4y agoIt has some interesting side effects. For example Zoom links don't work in the Flatpack version of Firefox. Ironically the Zoom app Firefox tries to open is in itself a Flatpack app. Not sure if this is by design or if there is a way to fix it.
- wishawa 4y agoFlatpak does exactly that. You can even fine-tune what folders you give to the app (Flatseal is great for this). xdg-desktop-portal makes things even better: app can only access files that you explicitly choose when prompted - kinda like on iOS.
- chlorion 4y agoFlatpak's sandbox is pretty weak and there are many subtle loopholes that allow for trivial escapes. Relying on it as a security measure is not a great idea. An example of such a thing, that is related to this thread, is the X11 socket being accessible even when the directory it appears to be contained in isn't bind mounted into the flakpak sandbox's mount namespace. This is because regular file system permissions do not apply to abstract sockets (which X11 can and does listen with). I think unsharing the network namespace would fix this, and configuring X11 to not listen with any abstract sockets might be possible, but this is just one of many examples of trivial sandbox escapes that most people would never even consider. The best bet to isolate untrusted software is to run it under a different UID (less safe) or inside of a VM (probably very safe).
- iggldiggl 4y ago> xdg-desktop-portal makes things even better: app can only access files that you explicitly choose when prompted - kinda like on iOS. Ho-hum. I can understand the appeal of that idea, but in practice quite a few file formats and applications rely on implicit and/or file-format-specific relationships between multiple files. I.e. I as the user pick one file for opening, but in order to successfully carry out that task, the program actually needs to access quite a few more additional files based on the initially opened file. None of the sandboxing approaches I've seen so far has a really great story for that usecase. AFAIK Android and Windows don't offer anything in that regard, no idea about Flatpak, and Apple at least seems to handle related files with differing file extensions, like movie.mp4 and movie.srt, but would still break down for more complex file formats where related/associated files don't share the same file name sans extension. Plus it means you always have to go through the official OS file dialogues and can't e.g. just manually edit a path directly in the app's UI if that would be more convenient…
- ThePowerOfFuet 4y agoI believe so too, and Qubes has been a refreshing change along those lines since I started using it. It's not for everyone, but I highly recommend it.
- SuperSandro2000 4y agoWhy is this a go program instead of 10 lines of bash?