We probably should run our games in containers. Anyone got an idea about how to do this? Isolate Steam/Origin/Games into their own little sandbox
We probably should run our games in containers. Anyone got an idea about how to do this? Isolate Steam/Origin/Games into their own little sandbox
Yes, we do it already. We pack Windows games into WINE, WINE into Flatpak, distribute it on torrents:
There you go, games in a container supported by piracy, with privacy out-of-box included: [DTH crawler website with magnets, might be blocked in your country] -> https://skytorrents.unblockall.org/search/all/ed/1/?l=en-us&...
Why people do have to do it? Some companies install spyware, other companies install a lot of 3rd party crap, DRMs that slow down games for paying users, don't support Linux platform despite promises...
Pirates will always be one step ahead, you can make a game with good user/buyer experience like CD-Project or great customer support - Darkwood [1] and make it win-win for literally everyone, or lose at some point.
https://www.gamingonlinux.com/articles/the-developers-of-dar...
ATM, I was focusing on e.g. fez from HumbleBundle through the AUR [0] and factorio [1]
As far as isolating software, there are a few possibilities, but sandboxing doen't always work. VMs are the way to go for now, but they're not foolproof either, and they come with a myriad of downsides.
Running apps in a sandbox should be the default behaviour for any OS by now. No app should have the privileges to access any file by default, except for files that are either created or owned by that app & user.
Sharing files between apps should be done as an opt-in basis, with explicit permission by the user, either file-by-file or per group of files.
"Trivial file conversion" tool can be implemented the same. The app tells the OS "hey, I want some files to convert" and the OS either grants access to a set of files/folders, or queries the user which file(s) (s)he wants to provide. IE the "open file" modal is the only window to accessing files. You can think of it like the HTML5 File upload & Drag/drop APIs, but a bit extended & more user-friendly.
Obviously smart engineers can think this through for longer than 3 minutes like I just did, and come up with better/user friendlier/safer solutions. But it breaks all backwards compatibility in almost any desktop OS
Only my backup tool gets root and can access other application's data - random trash games I download or even if I were to install them from pirated sources are unable to do that.
It's a vast improvement at the very least, even if not a perfect one.
There should be some very good definition for "App". I expect xz(1) to to be able to read any file I give to it (% xz myfile).
I would however expect chromium to only modify stuff in ~/.config/chromium ~/Downloads and be able to read only the libs it needs in /lib. But what about if I need to render an HTML page that's in ~/git/my.blog/index.html?
OpenBSD did some great things with pledge(2)[0] but truly fine-grained control like SELinux, AppArmor have met only limited success because of how complex they are to setup.
[0] http://man.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/...
Although I'm not sure what people are going to do. Run pirated copies with the malware removed?
(Which reminds me: when I ran a jailbroken iPhone years ago I had a fix for a PDF exploit much sooner than people having to wait for Apple to fix it, making running a jailbroken phone more secure (at that time).)
In my case, the gaming VM is shared by all windows games, but with some extra effort it is possible to isolate each game in a separate VM. (What comes to mind is using qemu qcow2 format for the base windows image, plus a snapshot file for each game installation)
You can either run Steam sandboxed which in turn will sandbox all the games it runs, or you have to do a bit of finagling if you want to individually sandbox your games.
It is mostly trial and error fiddling with the level on f restrictions you want while not breaking apps. In my case, i have a template profile of permissions, most of which are for restricting access to personal/confidential files/folders like Documents, Browser profiles, etc. Instead of blocking access outright though , i usually make the files/folders write-only..
So, for example the other day i wanted to download a 60fps video from youtube, and the only practical option was to use an adware ridden java downloader.. So i just downloaded it created a new sandbox (based on the template sandbox) for the app, installed it (i recall i had some minor kinks in the install process but managed to get it to work in the end). After i was done with it , i deleted the sandbox and i was off on my way without having to worry if the application had left some unsavoury bits on my system..
edit: I might add that a key advantage of Sandboxie as opposed to other solutions like VMs is that afaik, Sandboxie mostly works by intercepting API calls to the underlying OS.. This maybe more leaky than a VM, but it is also much more lightweight, and as a consequence it has given me good performance for stuff like games, etc.
What's to prove that sandboxie is not worse?.. [/tinfoil]
Seriously though, has it been audited?
"So for example the other day i wanted to download a 60fps video from youtube, and the only practical option was to use and adware ridden java downloader.. So i just downloaded it, created a new sandbox (based on the template sandbox) for the app, installed it (i recall i had some minor kinks in the install process but managed to get it to work in the end); after i was done with it , i deleted the sandbox, and i was off on my way without having to worry if the application had left some unsavoury bits on my system.."
edit: It seems Sandboxie was acquired by Sophos, so now you have to decide whether you trust Sophos or not.
Plus I would imagine that most gaming will require entering passwords at some point, whether that's into Steam, Origin, signing into humblebundle.com/etc.
>“This .exe file is from http://securityxploded.com and is touted as a ‘Chrome Password Dump’ tool,
Maybe that's another reason to use Firefox?
Even if my PS4 was online it still only has gaming related data on it.