3 ms·
The better answer is to build better OSes with better security models. I should be able to run a crypto wallet I downloaded from a Kim Jong Un fan site while h
by api 11mo ago
The better answer is to build better OSes with better security models.
I should be able to run a crypto wallet I downloaded from a Kim Jong Un fan site while high and it shouldn’t be able to do anything I don’t give it permission to do.
It’s totally possible. Tabs in a web browser are basically this.
I can do it with VMs but that’s lots of extra steps.
- netdevphoenix 11mo agoWeb pages have a lot of restrictions even if you consider the gradual adoption of the project Fugu APIs
- fuzzehchat 11mo agoIsn't that what Qubes is all about?
- api 11mo agoYes but IMHO that approach is a hack. “Fix our 1970s OS by putting it in a box in our 1970s OS.”
- colonial 11mo agomacOS kinda gets there. I've (grudgingly) come to admit that it has by far the best security story of any desktop operating system. Apps require explicit user consent to access the filesystem, peripherals, and other sensitive data (e.x. Discord requests "Input Monitoring" access to determine if you're "actively online" even when unfocused.) The only place it seems to fall flat is network I/O - LAN access requires permission, but dialing out to the wider Internet does not. Compare Windows, which has jack (except for bloated anti-malware hooks in NTFS.) Linux is _trying_ to replicate macOS with Flatpak/XDG portals, but those still need more time in the oven. Source: I use both a MacBook and a Linux desktop daily.