3 ms·
Linux comes in a wide range of distributions, so it is hard to make universal claims. One area where security defaults need to improve is sandboxing. If securi
by nextos 9mo ago
Linux comes in a wide range of distributions, so it is hard to make universal claims. One area where security defaults need to improve is sandboxing.
If security is a major concern, bwrap or firejail can easily provide that extra sandboxing.
NixOS and GuixSD make it quite trivial to sandbox applications in a declarative fashion using firejail.
An alternative is to use e.g. Flatpak, which gets you sandboxing for free via bwrap. But I am not a fan of application images that bypass package management.
- A_Random_Nerd 9mo agoI heard about the sandboxing being especially sketchy, thanks for a point in the right direction for mitigation. Additionally, any thoughts on snap? (presently looking into Flatpak)
- Shellban 9mo agoFunctionally, it is very similar to Flatpak. The main reason people do not like it (for reasons independent of sandboxed applications in general) is that Canonical controls the store and that it is not open-sourced, and that it is very difficult to remove it on Ubuntu setups (a major pain-point for people who need an unsandboxed Firefox setup).
- nextos 9mo agoI wouldn't use snap or Flatpak, just sandbox using bwrap or firejail. They are really easy to use. Containers also provide good development sandboxing. With distrobox you can run many distributions inside your own within a clean and isolated environment.
- iknowstuff 9mo agoJust use flatpak. Let's not steer newbies towards barely maintained untested bespoke solutions.
- bigyabai 9mo agoFlatpak uses bwrap, it's not esoteric folklore software. The OP asked a serious question and they're entitled to a serious answer.