6 ms·
Am I reading it correctly that because App Isolation is based on MSIX and MSIX requires code signing, that an app cannot be sandboxed unless it is signed? That
by ack_complete 3y ago
Am I reading it correctly that because App Isolation is based on MSIX and MSIX requires code signing, that an app cannot be sandboxed unless it is signed? That seems silly.
- pjmlp 3y agoThat is indeed the end goal, as revelead last year. "Modernize your Win32 application for security and privacy" - BUILD 2023 https://www.youtube.com/watch?v=w6VwHGPz12w https://www.youtube.com/watch?v=w6VwHGPz12w
- charcircuit 3y ago>That seems silly. That is already how it works on Android and iOS so I don't think it is very silly.
- jeroenhd 3y agoAndroid allows self-signing, though. The biggest use case of Android's signatures right now is to make sure only the packager can serve updates (and gain access to the data stored within the sandbox). You don't even need to provision any developer specific signing certificates to install these apps. In theory Android could start using certificate verification, of course, but right now that's not being used.
- charcircuit 3y agoThat's true. I hope with proper sandboxing Microsoft will allow self signed certs for such apps. I can understand the risk when an application can access literally everything of the user's, but the level of trust needed for sandboxed apps is less.
- creatonez 3y agoAn additional bit of context for why this is so annoying - Microsoft recently switched code signing to physical hardware only, meaning you must buy a server with a HSM, a USB security key, or use a more expensive CA. There's no longer any free CAs for this.
- mike_hearn 3y agoYou can use a cloud HSM and some CAs offer cloud signing. We described some info about setting that up with our tool in this blog post (it talks about Electron but the instructions work for any kind of app): https://www.hydraulic.dev/blog/21-shipping-electron-apps-from-ci-using-hsm-certificates.html https://www.hydraulic.dev/blog/21-shipping-electron-apps-fro...
- kuschku 3y agoSo how do I get one of these with my colo'd machines?
- creatonez 3y agoSearch "FIPS hardware security module"
- mike_hearn 3y agoIf you have physical access to your own server you could just plug in the USB devices CAs sell you. The cloud HSMs/code signing services are more for people who don't have hardware access and have to rely on someone else's HSM accessed over the network.
- mike_hearn 3y agoIt's mandatory on all sandboxing systems and for good reasons: sandboxing and identity are intimately related. To be usable the OS must cache permissions you grant the app but if your app isn't signed then nothing stops another app impersonating you and using your cached permissions. This is true for literally every user-facing sandboxing system even when it may seem that it's not the case. For example, the web ties app identity to the domain name from where it was downloaded, but asserted domain name isn't good enough so in practice browsers require SSL/TLS for most permissions (which requires a certificate and is a form of pseudo-"signing"). It's even true on Linux. The designs on Linux aren't as robust or decentralised as on macOS or Windows, but packages are signed there too by your distro provider. Although you can install packages from outside the distro and thus work around this system, by doing so you disable any protections against apps stealing cached resources (exception: I think Flatpak doesn't have this problem but it uses a more store-like model where the store operators are expected to stop apps impersonating each other and if you install other "stores" then all bets are off again). Now all that said. Conveyor (see my other post in this thread) can produce self-signed MSIXs, and those are fully fledged MSIX packages that will be able to take part in sandboxing when it's finally released. Installing such packages requires admin elevation because the installer has to add your self-signed root certificate to the user's trust store, and that's equivalent to overriding the protections (you could then sign an app as if it came from anyone). But it can be useful in corporate environments where the certificate is pre-distributed via Active Directory.
- actionfromafar 3y agoIt's still silly to not allow sandboxing of unsigned binaries. There could at least be a user sandbox where all non-signed apps can live. There could be an option for a temporary sandbox. And so on. There could be many useful options which would still improve security incrementally.
- mike_hearn 3y agoWindows already has that, it's a feature called Windows Sandbox: https://learn.microsoft.com/en-us/windows/security/application-security/application-isolation/windows-sandbox/windows-sandbox-overview https://learn.microsoft.com/en-us/windows/security/applicati... But this blog post is about App Isolation which is more conventional kernel level sandboxing.