3 ms·
Just stop with this nonsense. This is such a foolish opinion that is bandied about from a "I know exactly what apps I run, sandboxing is for those noobs" mindse
by yathaid 3y ago
Just stop with this nonsense. This is such a foolish opinion that is bandied about from a "I know exactly what apps I run, sandboxing is for those noobs" mindset. Did you compile them yourselves? Did you compile the compiler?
Let's just accept the fact that Linux comes from a place of "if you run a program you are responsible for what it does". This is contrary to modern users expectations of "just because I run a program it shouldnt be able to siphon all my data", largely driven by mobile apps and their ecosystem.
If I autocomplete an ls command on my Mac's terminal it will warn me that iTerm is trying to access the specified folder. There is nothing like that on popular distros. The whole security landscape needs to be re-thought.
Maybe someone who knows more than me can talk about bring features from more restricted Linux variants to a more broad audience.
- jolmg 3y agoHe's just bringing a valid point. Despite the lack of isolation between pieces of software, I too feel more confident about what's running on my Linux distros. That's not to say that "sandboxing is for noobs", but it's an interesting point. It's like how people in very rural areas can feel perfectly safe not locking doors and stuff, sleeping outside, etc., while that would be extremely foolish to do in the middle of certain cities, in certain neighborhoods. Different environments, different dangers, and I think it's fine to enjoy the benefits of a safer environment. Safety in this case is not provided by physical distance between homes but by curation of software done by nonprofit groups and selection of nearly only open source software with easy building of packages and tracking of changes in the source. > Did you compile them yourselves? Did you compile the compiler? There's no such thing as perfect security, and I think you know that. If you think your compiler may be compromised, there's stuff you could do, you just have to evaluate where the paranoia starts and stop before then.
- amstan 3y agoDo you trust your OS, compiler it was compiled with, and then trust all the hardware it's running on (which is probably even more insidious and capable of hiding stuff). Let's not pretend that just because there's a sandbox at a higher level of the stack and some kind of user ability to accept/deny operations that things are secure.
- tiberious726 3y agoEh, defense in depth, if we make a huge mess of overlapping detection systems, good luck inserting a compiler quine to bypass them all.
- tiberious726 3y ago> Did you compile the compiler? Do you trust trust? (And no differential compilation isn't an actual solution.)