3 ms·
IMO application sandboxing is very important, something that everyone should be able to take for granted in 2022. But the right approach is usually virtualizati
by voidmain 4y ago
IMO application sandboxing is very important, something that everyone should be able to take for granted in 2022. But the right approach is usually virtualization. If you omit functionality that people want, they come up with an (insecure) workaround and the workaround becomes required for common applications to work. If you deny requests by a program when policy does not permit them, by laziness or malice applications will require excessive permissions to function, and users will comply to get their apps working. Instead, every API must appear to be working to the greater extent possible, but sandbox all important effects and coeffects by default. So eg attempting to screen share from a program not authorized to do so either (a) prompts the user what to share or (b) shows an empty desktop with just that program.