7 ms·
Pro: A website can never steal your SSH keys, because firefox is limited, via unveil(2), to only seeing your ~/Downloads folder. Con: Every time you need to up
by radiator 3y ago
Pro: A website can never steal your SSH keys, because firefox is limited, via unveil(2), to only seeing your ~/Downloads folder.
Con: Every time you need to upload a file using your browser, you have to move it to this folder first.
- elric 3y agoYou can do similar things in Linux with firejail, but there are a lot of folks who feel uneasy about the safety of firejail.
- radiator 3y agoBesides firefox, more than 80 userland programs have their access to the filesystem restricted with the use of unveil.
- PrimeMcFly 3y agoIf Theo stopped being so resistant to solutions like AppArmor, then OpenBSD could have a real security layer instead of toys like unveil and pledge.
- thewanderer1983 3y agoHere is Justine's write up on pledge and why he wants to port it to Linux. https://justine.lol/pledge/ https://justine.lol/pledge/
- PrimeMcFly 3y agoIt has its uses I guess, but it requires opt-in which is a pretty big disadvantage, and then still can't do even a fraction of what SELinux can already do. SELinux isn't that hard to learn, and the security benefits are immense.
- okasaki 3y ago2024-01-08 22:34 ubuntu@knope:~$ sudo apparmor_status apparmor module is loaded. 185 profiles are loaded. 104 profiles are in enforce mode. (...) 124 processes have profiles defined. 122 processes are in enforce mode. including firefox and chromium
- artsi0m 3y agoBut apparmor is more complex system and in fact is an RBAC. unveil(2) is much more easier in implementation and enforcing.
- bayindirh 3y agoAlso, there's AppArmor which is enabled in Debian and SuSE which transparently limits applications' reach without they realize.
- belthesar 3y agoTransparent limitation is a double-edged sword. From an adversarial perspective, it's good since I'm not advertising what my system can and can't do, and poorly written software may get hung up on timeouts waiting for things to happen. On the other hand, those same benefits against an adversary are negative constraints to usability, as now silent failures can happen on a system, requiring you to watch your AppArmor logs like a hawk when using new software. Ultimately, less of a concern for servers that likely have limited scope and use cases, but a significant decrease in usability for workstations.
- bayindirh 3y agoYou need to write an AppArmor profile to limit your software. It’s an opt-in system. The workflow is you put a test system to “complain” mode and use your software as intended, and add the required permissions to the profile by looking at the logs to see what your app is doing. Then you put AppArmor to enforcing mode, add the profile to production system and your application is sandboxed. Iteratively refine as necessary. Debian desktop comes with AppArmor enabled. Nothing has been broken so far.
- mike_hock 3y agoAnd every time you upgrade to the next major release, you start again from square one because the requirements of your software have changed. You get it to work and things seem to be fine. Over time, you start noticing things that are subtly broken, until something just fails completely and doesn't work. The fix turns out to be trivial when you give it another go two days later, but at the time it happened you really didn't have the nerve to deal with it right then. After two dist upgrades, you realize that this approach isn't workable.
- Am4TIfIsER0ppos 3y ago"To upload a file move it to your downloads directory" lmao Can you "unveil" more places, without recompiling?
- codetrotter 3y agoIt would have cost them nothing to unveil a hypothetical ~/Uploads directory in the process of patching it to unveil ~/Downloads
- amatecha 3y agoYou can trivially-easily add it yourself by editing a text file, unveil is configurable per-process.
- codetrotter 3y agoTrue, but defaults are worth a million
- radiator 3y agoWith what purpose? Why do you want two different directories? On second thought, maybe you mean ~/Uploads could be unveiled read-only, though I still don't believe this brings much.
- SoftTalker 3y agoYes, configurable in /etc/firefox/unveil.main
- codedokode 3y agoUnveil looks like a hack or a patch. Why do applications have access to whole filesystem by default?
- bayindirh 3y agoBecause there's already UNIX file permissions which prevent applications to reach places they shouldn't. Confine a daemon to its own user, chroot it, and it's a sitting duck in its own universe. You add more layers with cgroup/AppArmor/SELinux in Linux, Jails in FreeBSD, unveil on OpenBSD, etc. You harden as much as necessary. Not "drowned by default".
- mike_hock 3y ago> Because there's already UNIX file permissions which prevent applications to reach places they shouldn't Right. Just set up a separate user for Firefox using a single unprivileged command from your user account or a few clicks in your DE, then launch Firefox as that user using another single command or click. Being subordinate to your main user account, the Firefox user's files and directories can easily be managed from your main user and you can move files between subordinate users using just an (unprivileged) chown or chgrp. Accidentally launching applications as your main user is not possible and the system strongly encourages you to create separate, subordinate users for all your applications and is designed from the ground up to make this simple and it works out of the box. Oh wait, that's not even remotely how any of this works. On a workstation, the "user account" is an almost completely useless concept (as set up and implemented in reality). That's why we have jails/namespaces/etc. Hacks that are piled on top of the useless mess of "user accounts" (all running as the same user, on workstations) trying to solve the same problems, but ultimately failing at providing any kind of comprehensive solution with a coherent vision. Software cannot take anything for granted anymore. Anything that looks like a writable file could be a read-only bind mount. Any mundane syscall could get it SIGKILLed for no reason other than that somebody forgot to add it to the whitelist. But from the user's perspective, there's no reasonable level of security by default.
- bayindirh 3y ago
- artsi0m 3y agoYou can edit /etc/firefox/unveil.main and add string like "~/Documents rwx" so it would be available from firefox