3 ms·
Besides firefox, more than 80 userland programs have their access to the filesystem restricted with the use of unveil.
by radiator 3y ago
Besides firefox, more than 80 userland programs have their access to the filesystem restricted with the use of unveil.
- PrimeMcFly 3y agoIf Theo stopped being so resistant to solutions like AppArmor, then OpenBSD could have a real security layer instead of toys like unveil and pledge.
- thewanderer1983 3y agoHere is Justine's write up on pledge and why he wants to port it to Linux. https://justine.lol/pledge/ https://justine.lol/pledge/
- PrimeMcFly 3y agoIt has its uses I guess, but it requires opt-in which is a pretty big disadvantage, and then still can't do even a fraction of what SELinux can already do. SELinux isn't that hard to learn, and the security benefits are immense.
- okasaki 3y ago2024-01-08 22:34 ubuntu@knope:~$ sudo apparmor_status apparmor module is loaded. 185 profiles are loaded. 104 profiles are in enforce mode. (...) 124 processes have profiles defined. 122 processes are in enforce mode. including firefox and chromium
- artsi0m 3y agoBut apparmor is more complex system and in fact is an RBAC. unveil(2) is much more easier in implementation and enforcing.