4 ms·
Sadly, Windows cannot do that. Every installed program has full disk access by default. It's very, very difficult to make it not so.
by andersa 5mo ago
Sadly, Windows cannot do that. Every installed program has full disk access by default. It's very, very difficult to make it not so.
- 0x073 5mo agoAppContainer (e.g. used in uwp or msix)
- andersa 5mo agoCan you configure that as a user for an unsafe program you want to run such as an online game? I think not.
- TiredOfLife 5mo agoWindows has had that feature for 9 years. https://learn.microsoft.com/en-us/defender-endpoint/controlled-folders https://learn.microsoft.com/en-us/defender-endpoint/controll...
- andersa 5mo agoThis is implemented the wrong way around. Each program should only have access to its own folders by default, with it being possible to grant additional access. Also, I don't believe Endpoint stuff is included in the normal Windows license.
- embedding-shape 5mo agoMaybe it isn't built-in, but most Windows user I've worked with, including myself, have been using Sandboxie for probably two decades at this point, probably hard to find any Windows software that is more ubiquitous than Sandboxie in developer circles.
- andersa 5mo agoSandboxie is essentially a giant pile of fragile hacks on top of a Windows API that does not want to be used this way. Does it seem like it works most of the time? Sure. Has it had bypasses? Also yes. I've used it in the past but I don't truly trust it.
- mfro 5mo agohttps://learn.microsoft.com/en-us/windows/security/application-security/application-isolation/windows-sandbox/ https://learn.microsoft.com/en-us/windows/security/applicati...