4 ms·
> Obsidian plugins have full, unrestricted access to all files in the vault. Unless something has changed, it's worse than that. Plugins have unrestricted acce
by ibash 1y ago
> Obsidian plugins have full, unrestricted access to all files in the vault.
Unless something has changed, it's worse than that. Plugins have unrestricted access to any file on your machine.
When I brought this up in discord a while back they brushed it aside.
- hsbauauvhabzb 1y agoTo be fair, it’s no worse of a dumpsterfire than any other plug-in ecosystem.
- esseph 1y agoIf you're using a flatpak, that's not actually the case. It would have very restricted access to the point where you even would have to explicitly give it access to user /home.
- pipes 1y agoSo if I run their software in a container they can't access my entire filesystem. I don't think that is a security feature. It sounds like if I ever run obsidian I should be using flat seal too.
- esseph 1y agoEr, what? I'm not claiming it's a security feature of Obsidian, I'm saying it's a consequence of running a flatpak - and in this situation it could be advantageous for those interested.
- s_ting765 1y agoYou're wrong. The obsidian flatpak ships by default with access to /home. https://github.com/flathub/md.obsidian.Obsidian/blob/5e594a4dc925b3edd928dd2ce6d9899b477e551f/md.obsidian.Obsidian.yml#L20 https://github.com/flathub/md.obsidian.Obsidian/blob/5e594a4...
- TomaszZielinski 1y agoI „love” such sandboxing defaults. Apps like Docker Desktop also share the whole home by default [1], which is pretty interesting if a big selling point is to keep stuff separated. No idea why node_packages need to have access to my tax returns :). Of course you can change that, but I bet many users keeps the default paths intact. [1] https://docs.docker.com/desktop/settings-and-maintenance/settings/ https://docs.docker.com/desktop/settings-and-maintenance/set...
- eli 1y agoNeeded for volume mounting to work easily I assume.
- TomaszZielinski 1y agoYeah, I forgot there’s the intermediate VM level, and user folders are shared there so that folders could be mounted to the individual containers using host paths.
- esseph 1y agoInteresting, I thought I had to turn that on for Obsidian! The first time I started installing flatpaks I ran into a bit of permission / device isolation trouble and ever since then, I use flatseal after installing an app to make sure it actually has access to things. I guess I misremembered in the case of Obsidian.
- HSO 1y agoWhat if you run little snitch and block any communications from obsidian to anything?
- formerly_proven 1y agoLittle snitch can block open(2)?
- 4ndrewl 1y agoI believe they're saying it can open, it just can't send the data anywhere. Seems a little excessive, but here we are.
- notpushkin 1y agoIt still can encrypt everything and demand you pay some ₿₿₿₿.
- lxgr 1y agoIf it can open and write any file on the OS, it's pretty much game over. Too many ways to exfiltrate data even without network/socket access.
- HSO 1y agoWorse, what keeps this from editing the config files for Little Snitch (or similar blockers)?
- TomaszZielinski 1y agoI believe LS has some protections against this. Never tried them, but there are config related security options, incl. protection against synthetic events. So they definitely put some thought into that.
- 4ndrewl 1y agoFile system permissions?
- Tallain 1y agoHaving recently read through a handful of issues on their forums, they seems to brush aside a lot of things. It's a useful tool but the mod / dev team they have working with the community could use some training.
- deleted 1y ago[deleted]
- raybb 1y agoAh I guess that's one reason some folks started running it in a docker container. I think Linux server recently released a container for it.
- qbit42 1y agoIs this true on Mac? Usually I am notified when programs request access outside the normal sandboxed or temp folders. Not sure how that works in any detail though.
- eli 1y agoTo be fair it also ships with the ability to install community plugins disabled.