3 ms·
> sandboxing is pretty important and an area were Linux distributions are falling behind macOS How so? Linux has cgroups, namespaces, containers, and things li
by totallywrong 3y ago
> sandboxing is pretty important and an area were Linux distributions are falling behind macOS
How so? Linux has cgroups, namespaces, containers, and things like Flatpak. And these days rootless containers (where you can set even the allowed syscalls) are good for most use cases too.
- nextos 3y agoIn practice, mainstream distributions do not offer ready-to-use zero-conf sandboxing for userland applications. There are of course exceptions, like those using Flatpak, but what I would like to see is Firejail/bwrap applied to all binaries, with sane defaults. In other words, if I run python or Firefox and they get compromised, they should not be able to read e.g. ~/.ssh and steal my private keys (unless I gave them permission to). Nix has done a great work making dependencies declarative and reproducible, I would also like clean sandboxing as it is an equally important issue.
- imglorp 3y ago> Firejail/bwrap applied to all binaries, with sane defaults Isn't that kinda SELinux in the limit?