5 ms·
running all apps in something like a lite version of docker in user namespace mode would implement this
by fswd 4y ago
running all apps in something like a lite version of docker in user namespace mode would implement this
- microtonal 4y agoSuch solutions exist already, see e.g. bubblewrap [1]. The Flatpak ecosystem is slowly trying to add protection by sandboxing applications using bubblewrap. However a contingent of the Linux community meets this with: - Flatpak is terrible because it doesn't follow a file system hierarchy that was invented in the 70ies. - Flatpak is terrible because my early 90ies package manager is the pinnacle of packaging. - Flatpak is terrible because I only trust my distribution's packages. - Flatpak is a security nightmare because it doesn't isolate every application now. (Which is not really possible, because applications/toolkits need to be adapted). - Flatpak is terrible because now my applications cannot open arbitrary files anymore (including ~/.ssh). Conservatism is what holds the Linux ecosystem back. We have seen this story before with systemd. This is sad, because Red Hat and others are doing fantastic work modernizing Linux (see Flatpak, Fedora Silverblue, etc.). [1] https://github.com/containers/bubblewrap https://github.com/containers/bubblewrap
- npteljes 4y agoQubes OS does it exactly like that: https://en.wikipedia.org/wiki/Qubes_OS https://en.wikipedia.org/wiki/Qubes_OS