4 ms·
Yeah, I guess most existing Linux stuff that is actually configured (so not SELinux etc) is geared at system processes not user ones. Transparently running all
by ratorx 2y ago
Yeah, I guess most existing Linux stuff that is actually configured (so not SELinux etc) is geared at system processes not user ones. Transparently running all user applications in properly isolated containers would be quite neat.
Does Firejail handle dynamic access (eg. I may want an xz invocation to work on my private keys, but not THIS specific one where I’ve given it a completely different file?).
I quite like pledge/unveil for this kind of thing on OpenBSD, although that’s for a different threat model.
- nextos 2y agoFirejail and bwrap are setuid sandbox frontends. You can wrap e.g. a new xz invocation to let it work on your private keys. But Nix relies on ephemeral shells and flakes, and they don't play so well with each other. The interface is clumsy. Guix, in contrast, has a pretty nice set of CLI switches for these features. Even normal distros should prioritize some simple graphical UI for this. Running programs with minimal privileges would result in a significant enhancement of security. The kernel features for achieving this are already there.
- NekkoDroid 2y ago> Firejail and bwrap are setuid sandbox frontends. bwrap does not require SUID, it only needs it if user namespaces are disabled for unpriviledged users.
- sirspamalot108 2y ago[flagged]
- deleted 2y ago[deleted]