4 ms·
In Linux, is there a secure, but also convenient and user-friendly, way to prevent processes from having the same default level of access to the filesystem as t
by lovelearning 4y ago
In Linux, is there a secure, but also convenient and user-friendly, way to prevent processes from having the same default level of access to the filesystem as the human user?
I like Android's system of per-app uid/gid. But AFAIK it's not implemented by any mainstream Linux kernel or distro.
There's AppArmor, but the last time I tried it, I came away with the opinion that it's not very convenient or user-friendly. Perhaps some kind of friendlier CLI or GUI frontend may help.
I'm assuming SELinux can achieve this but I don't have first-hand experience with it and from what I've read online, it seems to be less user-friendly than even AppArmor.
Any other approach you know about? Do secure distros like Qubes OS or Tails implement this systematically?
- paskozdilar 4y agoContainerization is what you want. There are many containerization tools for Linux, Docker being the most popular, and systemd-nspawn being the most Linuxy, but a bit unknown.
- lovelearning 4y agoI didn't know about systemd-nspawn — thanks for the suggestion. I already use Dockerized aliases for some CLI apps (e.g.: ffmpeg) but I didn't find the approach as convenient as I'd like. I've found docker mounts difficult to secure. I'd like to mount $HOME but exclude even read-only access to "$HOME/.ssh/", "$HOME/passwordsafe.pwsafe3" and a dozen other sensitive file patterns. Some kind of predefined "access profiles" to create FS access rules and assign processes to them ("assign all python processes to python profile") is probably what I'd like. Containerization is probably the best approach but I'd prefer if it's more opaque and less effort than Docker. For example, if I create a pyenv environment and run its 'python' command, I want that python process to not have full access to the filesystem without having to create container images, command aliases, or volume mounts.
- paskozdilar 4y agoIn that case, you should look into NixOS/Nix package manager (or, if you're a GNU fan, GuixSD/Guix package manager). I've heard a lot of good things about them related to your problems, including extremely good support for virtual environments of any kind.
- paskozdilar 4y agoI hacked up a bash script for running arbitrary command in docker container, mounting only PWD. It traces dynamic libraries through ldd and creates a new image for each unique command. I got it working for ffmpeg: https://github.com/paskozdilar/dockerify https://github.com/paskozdilar/dockerify I might try to optimize it a little bit later, perhaps bind-mount dynamic libraries instead of creating a new image for each command.
- Beltiras 4y agoAlso: don't install curl in your container.
- yrro 4y agoContainers don't contain. You have to assume that any code running inside a container has broken outside of its mount namespace & can interact with anything running on the host. Only Linux's traditional mechanisms (credentials; capabilities; SELinux policy; others are available) are able to defend against this.
- progval 4y ago> I like Android's system of per-app uid/gid. But AFAIK it's not implemented by any mainstream Linux kernel or distro. You can create users manually for each app. For GUI apps, https://firejail.wordpress.com/ https://firejail.wordpress.com/
- lovelearning 4y agoA once-over of the docs seemed to tick a lot of my boxes. I'll check it out, thanks!
- planede 4y agofirejail is not limited to GUI apps, is it?
- Mr_Yolokovich 4y agoThe "user-friendly" part is always tricky. Maybe you could give bubblewrap a go. I think that it strikes the correct balance between inconvenience and security. I use it to wrap different package managers like npm. https://github.com/containers/bubblewrap https://github.com/containers/bubblewrap
- fmajid 4y agoman -s 7 capabilities I’d like to see something like OpenBSD’s pledge/unveil. These all work at the process level, though, not individual portions of code in a process.
- pabs3 4y agobubblewrap, which is used by flatpak's containerisation, is a great tool for modifying the view of the filesystem seen by particular processes. You can even containerise processes installed in your rootfs.
- WhyNotHugo 4y agoAs others have said, containerisation is what you want. If you want something low level look at bubblewrap (brwap). Firejail is also another tool to do this, a bit higher level and with more features (maybe too many IMHO).
- yrro 4y ago> In Linux, is there a secure, but also convenient and user-friendly, way to prevent processes from having the same default level of access to the filesystem as the human user? SELinux, if it was easier to use! Apparmor Bubblewrap? If anything the problem is that there are too many mechanisms and most users are familiar with none of them...