2 ms·
My desktop apps can’t trace other apps because they don’t have my sudo password. Some of my desktop apps run in containers/snaps or whatnot and other user proce
by zbentley 2mo ago
My desktop apps can’t trace other apps because they don’t have my sudo password. Some of my desktop apps run in containers/snaps or whatnot and other user processes can’t get to their internals without pivoting to root. Apps can’t read each other’s memory because of segmentation.
There is a lot more to desktop inter-app security than “if an app had a root shell then it could compromise things”. A great many attack vectors that we see constantly have a much narrower ingress than that.
- M95D 2mo agoYou don't need sudo for trace under the same account. You can even attach a debugger and read all app's memory. Virtualization is another thing entirely. But if you want it that way, then why not simply start a second X for the untrusted app?