Windows Sandbox
techcommunity.microsoft.com
techcommunity.microsoft.com
I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions.
The thing that annoys me more (hi MS guys, feel free to tell the relevant people about this) is how they have started to add ads to the login screen and my start menu - even in the Pro version!
I'm on KDE now so I cannot verify this since the last few months, and probably shouldn't care but given that MS has become a lot nicer in a lot of areas it really should bug developers and PR people there that PMs or bean counters (sorry to all good accountants and PMs out there) are allowed to destroy all the work you put into making people love you.
Edit: minor edits for readability, clarification
A coworker has asked what reasons I could have for not wanting to run "the best OS". this is enough for me.
- Clumsy installation process (unless you where in a position where you didn't have to rely on OEM crap, i.e. unless you where an IT pro or enthusiast)
- Performance. My builds would easily take 50% more time on the same hardware with Windows. Git was slower. Node was slower.
- Ecosystem. Until WSL getting access to standard tooling was kind of clumsy (respect for Cygwin, but still). Even after WSL it is still clumsy (who can tell my how to activate WSL without consulting duckduckgo? I've done it twice and I still cannot say for sure).
- Package management: Used to be non-existent (except again cygwin). Now it is just clumsy (a mix of Windows Store, WSL apt-get and Chocolatey should get you most of the stuff you need.)
- Licensing. I'm no die hard free software person, but many of the standard programs on Windows are directly user hostile (Acrobat Reader comes to mind).
- Until recently Windows also lacked basic desktop manager features like multiple desktops.
- Not directly Microsofts fault, but if people like me are using Windows it is often because someone I work for demand it. Usually that also means having to deal with an IT department running Active Directory and all the "interesting" consequences that has, even for someone who is part of said IT department like I've been. (Getting locked out from your files because an admin flipped a switch? Check! Someone swapped regional settings across a group of machines that I was responsible for and locked them, causing all POS systems to fail with no way to fix them? Check! Having to wait for all kinds of scripts that run on logon? Check! Accept having basic parts of your user experience set by it department? Check! Again this is not MS fault directly but back when I first experienced working with Windows in companies for some reason Active Directory seemed to attract people who wants to to those kinds of things and/or it has a power to make them want it. </rant>
LTSB is (IMO) the best version of Windows since 2000, but it still ain't good enough to be my daily driver.
I've not found a way to stop Defender from advertising Microsoft accounts or OneDrive via the security warning system. But they can at least be dismissed until the next feature update puts them back.
This is damning praise. If intentional it means users are't being offered permanent control of the software, only momentary changes. I dare say they aren't even 'options' at that point since the word implies lasting choice; at least for me.
Hyper-V does function under the garb of 'Windows Hypervisor Platform' and 'Virtual Machine Platform' even under Windows 10 Home. I have it installed and it provides the virtualisation capabilities for Device Guard and Core Isolation/Memory Integrity.
Virtualbox from version 6 has been forced to fallback to Hyper-V when the latter is running, as it doesn't relinquish control to another virtualisation software.
So there is no reason why MS cannot implement Windows Sandbox even on Home since the underlying tech actually functions on all Windows editions, provided hardware support is there.
By that logic Microsoft could also allow Windows 10 Home to run Active Directory. The reason there's a Pro/Home split is a commercial decision not a technical one, so trying to view it through a technical lens is faulty.
Regardless, if we want to talk about security features Windows 10 Home "should" have, let's talk AppLocker one of the most powerful security tools available. My computer illiterate relatives aren't going to be dropping into Sandbox to test potentially dangerous executable, but AppLocker could be set and forget, blocking execution of dangerous items.
The only thing Microsoft offers on Home is the highly self-serving "Allow apps from the store only." Which adds as many problems as it solves.
You misread the post.
eitland was saying that: 1) sandbox needs hyperv for technical reasons 2) hyperv is not in home for commercial reasons 3) therefore home can't have sandbox
Santosh83 wasn't trying to view the entire thing through a technical lens. Their post has an implicit understanding of the commercial argument when it comes to unlocking the full hyperv feature set. They were simply correcting the technical portion of someone else's argument.
Take a car wreck
Even in Windows Server, Windows Explorer includes links to Videos and Music as default. Why....
Now when it comes to things meatier than a few shortcuts they are much more willing to go modular. See nano server.
IMO running an app in a sandbox should be the default option.
On Windows, I used to like sandboxie, which virtualized every write into single directory. Uninstall was easy as removing that dir.
This MS sandbox doesn't allow you to continually run an app in the sandbox, as all data get's destroyed on app close, so it's not sandboxie (or similar) replacement.
But I was talking about all files that app creates. Like files in home dir (eg. ~/Library). If you remove the app, those files stay there and occupy space.
The only way you can partly clean up the mess, is to delete home dir from time to time (but backup important files first). Even then, there might still be files in /usr/local etc.
For example, the other day I moved Word to the trash, 5 seconds later I get the AppCleaner pop up letting me know it found an additional 2GB of shit that Word just littered around my machine that wouldn’t have gotten removed by just deleting the app. And unfortunately, that definitely hasn’t even been the worst offender I’ve run into, and at this point I’m very rarely not surprised by the amount of leftover crap that doesn’t get removed when deleting an app.
This has always been the case on Windows. In fact if anything, nowadays it’s better than its ever been because thanks to the UAC and other controls Microsoft have put in place, developers aren’t so free to do whatever they like to the host machine. But that’s remember a time before the UAC when it would often be common practice to reinstall the OS on a semi-regular basis (not something I personally engaged in but a great many of my peers used to).
> And it’s same on all known OSes
It really isn’t. On platforms with a proper package manager you can query what files get installed where. A great many package managers even let you query a file system file and see which package installed it.
Of course you still have the problem of the software writing files during its operation but that should be limited to $HOME (on POSIX systems) or any path that is writable by the owner / group of the user that application runs as (which should be limited even if it’s a system service).
Even the UAC aside, on Windows you now have the application data directory and permissions on the registry which both take some reliance off random files dumped anywhere. Before then Windows was like the wild west. And we're not talking that long ago in terms of the history of Windows - Vista was released 11 years ago and it took a few years after that for developers to catch up.
Plus with the trend of moving everything to the web, you're getting fewer native applications which can write those random files in seemingly random locations (that's one of the few good things about the move to web applications in my personal opinion).
You'll always have problems with developers having their own opinions - that's inescapable. But things used to be so much worse.
I think you need to support that statement. I believe the vast majority of software on common Unix distros creates no files in $HOME[1], and of those that do the majority use one folder in home[2], which *should+ be used for configuration, and often you don't want it automatically uninstalled on software removal.
The few I can think of that quote to multiple locations do so because the extra locations are shared folders. For example, I would not want my downloads directory removed on uninstallation of Firefox.
1: E.g. Most things in /bin, and /usr/bin.
2: other than what I outlined above, I can't think of any that use multiple directories. If it's truly a common as you say, you should be able to provide some examples.[0] https://specifications.freedesktop.org/basedir-spec/basedir-...
Those proper package managers still rely on the packager doing things correctly - just as it would creating a windows .msi.
There's plenty of linux packages that creates files during operation in their designated /var/log/xxx /var/db/xxx /etc/xxx /home/xxx/ directories that you're not able to query using the package manager.
Not to hot on linux management options I just install the thing over and over.
Those two paragraphs are talking about different OSs. 1st paragraph is talking about Windows, 2nd paragraph is talking about non-Windows systems with first-class package managers such as ArchLinux, Debian, CentOS, FreeBSD, etc.
> Those proper package managers still rely on the packager doing things correctly
Sure, but the point is you can query what the package manager has done.
> There's plenty of linux packages that creates files during operation in their designated /var/log/xxx /var/db/xxx /etc/xxx /home/xxx/ directories that you're not able to query using the package manager.
That's half true. You can query that /var/db/xxx and /var/log/xxx has been created by the package manager and often the directories (and their contents) will be owned by the user which the daemon runs under.
However I do agree with the point regarding your $HOME directory and actually made that point myself:
> Of course you still have the problem of the software writing files during its operation but that should be limited to $HOME (on POSIX systems) or any path that is writable by the owner / group of the user that application runs as (which should be limited even if it’s a system service).
As an aside, you can also query what files a particular application has open. In fact there are a few ways to do this from querying the /proc/$PID directory through to tools like `lsof`.
I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do.
Pretty much all OSs, including windows, have ways to view which processes has a file open
Got any examples of that? You'd expect only docker to write to /var/lib/docker, mysql to write to /var/lib/mysql. etc. Not discounted that I've overlooked something but a quick look in my /var/lib and it's easy to see what is managed by what. So I'm curious what instances you have of a package manager creating a directory and then a completely unrelated daemon writing to that directory.
> I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do.
I'm not claiming they solve all the problems - in fact I literally identified a few problems they don't solve! Plus even those points I identified aside, there will always be edge cases for thing that package manager should have solved but failed to do so.
Perhaps we should turn this discussion on it's head and discuss better ways to solve the problems people are describing? What would your solution be? Or are you ostensibly agreeing with my points but being contrary just for the sake of playing devils advocate?
> Pretty much all OSs, including windows, have ways to view which processes has a file open
Isn't that literally what I just said? (plus I gave a few examples too).
Not the person you were talking to, but looking at certbot, it puts files into /lib/systemd/system/ and /etc/cron.d/ with root:root.
I shouldn't expect too much in /lib/systemd/system is installed outside of package managers but I agree it does happen and at least they're generally quite easy to identify which service file does what.
crontab is definitely one of those nasty things that can often get forgotten about though (and I speak from unfortunate experience there hah!)
We're really drifting into the domain of Puppet and it's ilk now though.
dpkg -L helps a lot when figuring out where all the files get spread.
Well yeah, that was the central point of this conversation :)
The really tricky problem is when a package must modify an existing shared resource. Such as appending lines to an existing config for example.
Pacman creates a .pacnew file and lets you merge it yourself for this very reason.
Obviously this wouldn't be to everyone's tastes but it's good that market is catered in my opinion (but then I would say that as I'm very much a hands on person).
This is currently solved by having applications support both a config file and a config.d directory. The primary owner (package) of the resource modifies the conf file, while secondary packages drop their own config in conf.d/${package}. Numerous examples exist: logrotate, rsyslog, apache, nginx, systemd and apt come to mind.
ps: coincidentally, I was just starting to use linux firejail on a daily basis.. very very useful.
It's true that Linux package managers used to be buggy and problematic in the 90s but those days have long since gone. And while I'm not discounting that a package upgrade could damage your system, the instances when they do are highly unusual rather than a typical problem users face with each and every upgrade. In fact Windows sysadmins have far more dread with running Windows updates than Linux admins do and yet Windows updates are only focused on Microsoft products rather than every piece of software on the system.
> It's all up to packagers to author their packages right so they don't leave garbage on your machine that you have to manually clean up (or give up and reformat).
Actually it's not. It's up to the application developers to do that. If you specify a package to install a file `x` to location `y` then the package manager will uninstall that file automatically too. You don't specifically need to tell the package manager to do that (or at least not with any of the packaging systems I've used). But if the application developer writes the application to spew out thousands of files into $HOME, that happens outside of the package manager. There isn't a whole lot you can do to stop that aside limit the directories which your application has permission to write to (either via chroot, containerisation, user/group permissions, SELinux, or other forms of ACL. There's actually plenty of tools on Linux / UNIX to handle that problem).
I actually always run that way most applications that do not fully adhere to the XDG base dir specification.
File writes for application files are rarely the problem any more.
The problem is that in order to function correctly (For some definition of correct, but say e.g. to associate file extensions, create shortcuts, start automatically, install a dependency such as a C++ runtime patch, whatever) the program needs to write to subsystems of the OS in a non-reversible way. It's also very HARD to do these things (create setups) because systems like Windows Installer aren't trivial to use. Every time a setup author makes a mistake there is a risk of stuff being left behind.
Fundamentally, what you are doing is you are in state A when installing the program, creating state B. Then you continue to modify the system simply by using it or installing some more software creating state C. If you now uninstall the first software you don't have anything but a script undoing A->B, which run backwards can only do B->A, but you are in state C and you don't want to first run C->B because you want to keep the other parts of state C. So the uninstall script has to run in unknown territory (a file may have changed, a later dependency version may have been installed globally, a registry entry may not exist because they are NOT isolated per application etc) so the uninstall script just has to do what it can.
A sandbox could be a solution to this, where the sandbox contains diff views over some immutable base image. It probably is a lot easier to do (and do efficiently) with OS support.
Unless I am mistaken, I don't think this is the case for iOS, Android, ChromeOS, FirefoxOS, and many game consoles.
This is really just a problem with desktop and server operating systems, not with operating systems as a whole. It's also getting bettwe with package managers, the Windows Store, and UAC.
At least on Windows I have my pick of thousands of Portable Apps (and most Windows software can act as a portable app if you just extract it without installing it anyway, albeit still leaving junk in the registry). You know what's a great feeling? Being able to reinstall your OS and just pointing a new toolbar at wherever you keep your portable apps and being good to go.
If I download an app, I’m anticipating a .dmg to mount, which holds a self-contained .app which runs anywhere, and a link to /Applications, to suggest a sensible place to put it.
It’s not enforced, but it is the norm.
I guess you're missing one. Android allows you to remove everything that app created.
Seriously this is a killer feature needed by everybody. And specially the non-pro users.
Windows SKU has nothing to do with hardware.
https://www.dell.com/en-uk/shop/2-in-1-laptops/new-xps-15-2-...
Actually I can't seem to configure that directly from dell to come with Pro lol. Seems there's a question about that too.
1: https://www.dell.com/en-uk/work/shop/tablets-and-2-in-1-lapt...
2: https://www.dell.com/en-uk/work/shop/laptops/new-xps-15-2-in...
Also I don't think your parents want to use that particular sandbox. There's no persistence at all: no bookmarks, no cookies, no history, no local documents, ...
That way for your parents they just have to buy the pc, put the usb in and reboot it, and then call you when it's back on so you can remote in and give it a key and finish configuring it for them. I suppose even that might cause issues if you can't teach them or walk them through via facetime how to set the device to boot from the usb instead of the harddrive.
Microsoft should make it easy to download, install and update on all non-Enterprise versions of the OS. This will also greatly reduce instances of a random ransomware holding critical data hostage and doing irreparable economic damage to small businesses (as was visible during the WannaCry episode last spring [0]).
[0] https://en.wikipedia.org/wiki/WannaCry_ransomware_attack
I'll take this one step further: Microsoft should make this as easy as "right click > Run in Sandbox". It would make the lives of everyone so much easier.
It is an evolution of desktop bridge, appx and msi.
Does it add a simple context menu entry to convert an installer? Bonus points for straight up Install and even more for Run.
I see it's open source, so if it's missing it may be possible to make a distribution of it with those things implemented. Then one could install it and make it a default msi handler.
Edit: from what I see conversion is much more involved. Create a certificate and go through a wizard and fill out some forms. Correct me if the is a quick and easy convert option. Otherwise it's a nice thing that needs more development to be useful for a generic user.
https://blogs.msdn.microsoft.com/sgern/2018/06/18/a-closer-l...
A generic user is supposed to just double click on an *.msix file to get it installed on the Windows Store infrastructure.
This sounds like someone making installer stuff would say. MSI will be supported on modern OSes for much longer than "a few more years".
VB6 apps created in 1998 will be supported until 2025 at least. MSIs will be treated the same.
The alternative is to convince some engineers to create this same feature in their spare time and contribute it for free as a Linux package. Then they can get email about all of the things it doesn't do, and fix bugs in their spare time on a feature that all they see are complaints for. Until they burn out and the repo goes dead for a while and then gets picked up by one of those users who wants the feature to exist, and they make some improvements and get into an argument with another user who forks it and now there are two of them, almost the same but with a few features that are unique to each one. Of course for most of the users they either don't care and load one at random, or they do care and find features from the "other" system they want in the one that is being used. They send mail to the maintainers asking them to copy those features. Which adds more pain as the developers copy each other's features but they put their own special spin on them. This burns out more developers and a third person comes out and writes their own syntactically incompatible version that is functionally identical to the two different 'legacy' versions.
At this point I just pay the man his $100 and appreciate that the people working on the code are on it all day and can spend evenings with their family.
"You told me to use sandbox to be safe, so I wrote critical document X in a sandbox because I want it to be safe, but now that I rebooted I've lost all of my work."
It's probably nowhere near as elegant as the Windows 10 feature, but it should be very handy if you have older versions of Windows!
I've used it many times on occasion but always end up uninstalling it because it makes such simple things so complicated.
But yes, it's UI is horrible and might be difficult to setup (apps with incorrect setup might not even run).
This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.
Actually, I think it would be hard to find an enterprise software vendor who wouldn’t want to include extra functionality in their premium SKUs as a way to further differentiate them and encourage up-sell.
Last time I bought one of these 15€ keys for a friend, I had to write to the customer support over 10 times and shuffle through at least 6 different keys until one actually worked.
Nonetheless, if you can go from Home to Pro with 13€ it feels quite ridiculous that there is a Home/Pro distinction at all from the very start.
The case in point is it’s putting lipstick on a pig at this point. Every change that is made comes with another security or friction factor. Every problem solved creates two more.
They need to stop adding shit to it and fix what is already there.
- "One of the key enhancements we have made for Windows Sandbox is the ability to use a copy of the Windows 10 installed on your computer, instead of downloading a new VHD image as you would have to do with an ordinary virtual machine." - "we also allow Windows sandbox to use the same physical memory pages as the host for operating system binaries via a technology we refer to as “direct map”" - "More recently, Microsoft has worked with our graphics ecosystem partners to integrate modern graphics virtualization capabilities directly into DirectX and WDDM, the driver model used by display drivers on Windows." (Note: it also works with OpenGL nowadays too)
Maybe you can achieve your workflow needs from Home + free 3rd party virtualization software but if you don't see anything special I'd recommend reading the article more carefully.
All other virtualization software runs fine on Windows Home.
I'm worried that this is going to be the compromise we're all forced to make in the future.
There are obvious alternatives to ChromeOS that are just as secure and just as inexpensive (especially if you have some old hardware just laying around, or else you can just buy refurbished hardware - just about anything made in the last 10 years will do, if not more than that) - and not any less useful than a Chromebook. And they can be updated for as long as the hardware keeps going - they won't suddenly become "unsupported" after a mere five years.
You can easily imagine that in the future hardware manufacturers will remove the ability to install a 3rd party operating system. It's already essentially impossible on a locked-down Apple iOS appliance.
In terms of usability I have to tip my hat to Google. ChromeOS is very easy to use so far. Probably until chromebook vendors start adding all sorts of their own shitty tools and accounts like Huawei has done with their phones.
That's just the start, people store private stuff on their computers you know. Photos, letters, bank transactions, emails, contact lists.
Microsoft choice to make this not only non-default but even a premium feature is inexcusable. I already switched to Ubuntu for this reason alone. Now my life is much easier for many other reasons as well, like Docker.
None of this is good, for anybody involved. IT security is like vaccines, it only works if everybody's got them. This one of my biggest issues with the current "ads let us have free software" defense of the advertising craze. Ads let us segregate users based on what features they can afford not to have, and unfortunately for most laypeople it's security and privacy that's on the chopping block.
What a mess. Typed from my iPad Pro.
Yeah... Good luck running the latest version of iOS on an older iPhone. (Many are still have a 5/6 and you really don't want to update those if you value a reasonable experience and latency.)
IOS 12 can be installed on the 5S, which is the oldest 64 bit phone. It was launched in 2013.
My kid has it on a 6, and it's legitimately good performance there.
Good luck getting the latest Android onto a 5 year old handset without jumping through some non-trivial hoops.
[1]: http://www.iphonehacks.com/2018/09/ios-12-performance-improv...
I also have an iPhone 8, this is an Ok phone but is a worse experience than the 4 year old Android phone. Despite the cost being much higher, the screen is worse quality, for instance.
My partner has a 6 and it is remarkably slower than both. To the point where you sometimes just want to give up on whatever you were trying to do while waiting for a map or Spotify to load.
Maybe your experience is different to ours, but I'm only reporting what I see from using all 3.
iPhone 8 vs Nexus 6 from 2014, back when Google marketed that series as reasonable Dev devices, not necessarily flagships.
326 ppi vs 493 ppi
750 x 1334 pixels vs 1440 x 2560 pixels
IPS LCD vs AMOLED
Somewhere there is a tongue in cheek meme comparing a sister phone, the Nexus 4, from 2012 against a 2016(?) iPhone and it's quite interesting how many features the Android phones had and were mildly credited for that when copied to iPhone were /world changers!!1/
Granted, Android phone manufacturers have wised up and besides things like the Nokia 6.1 you can't really get a good mid-range Android phone any more... it's mostly clustered around either the humble Moto E or the Note 9 price points.
You're lying. Installing a custom third-party Android ROM is way more than a 10 minute process, your OnePlus X is barely more than 3 years old, and there's a huge difference between a random OS image you downloaded from a forum online and manufacturer-supported OS updates for a 5 year old phone.
Spoken like someone who's never actually used a 5 or 6 running iOS 12.
Also have an 8, which admittedly is an ok phone if horrendously overpriced but work paid for it so I can't complain.
I think this is why we need legislation: The free market obviously can't sort this out to peoples' benefit.
I have a couple Android devices I can't figure out how to update, so I'm afraid to use them for anything serious. If the author isn't responsible for writing crappy code, and I can't fix it, then where's my lemon law?
Am I the only one who doesn't see where the roughly $1000 price gap between the Honor Play and the newest(?) iPhone XS Max?. Their brand is really not worth that much to me anyhow.
"iPhone: About 1250 EUR, Honor Play: About 320 EUR" [1]
[1] https://www.gsmarena.com/compare.php3?&idPhone2=9230&idPhone...
So, yes, it is reasonable to be angry when they put advertisement on the hardware that you paid on the OS that you paid together with the hardware. It is creepy, and belittling too.
Luckily IT professionals have yet the choice to install something else. Let's see how long it takes until we have no choice what software is allowed to run on devices that we buy.
Sorry for the rant.
By way of comparison, I willingly and happily pay more to use Apple hardware and software specifically because that money buys me a hell of a lot more privacy, security, and functionality than the equivalent amount of money would buy me in the Microsoft / PC ecosystem.
> most expensive version of their OS.
> they charge hundreds and hundreds of dollars for.
To be clear here, I'm not defending Windows. I agree with you that what they do is not constructive for their users. I'm merely pointing out it's ironic for Mac users sit on their throne and decry Windows' practices while paying significantly more for non-upgradeable Mac hardware when if you really gave a shit about security and privacy, you'd buy reasonably priced PC hardware and install a linux distro.
Last I checked, App Store is absolutely filled with advertisements that I didn't request. Why is it so significantly worse that Microsoft happens to place theirs within Explorer? I think both are rather frustrating when you already paid for the software and/or hardware.
And do you have any reasonable complaints about the security and privacy of a modern Mac with the T2 chip, or are you saying that anyone who cares at all about security should run Linux and spend 30% of their time wrangling with SELinux policies?
And both 13" and 15" Dells have a fingerprint sensor which is as snappy as Touch ID without being bundled with a thin strip of touchscreen and a $200 price hike.
That's because these laptops are designed to be serviced on-site by repairmen who are not always so bright. So I imagine, similar HP offerings are as robust.
Dell's and HP's phone support and warranty support are super awful, though, so this may be a factor for you. For me, the difference between a drink spill costing $600 (and I do it myself) on a $2500 Dell versus $1500 (and I have to lose my files/get a new system) on a $1600 MBP (both true stories) is significant and I'm not rich enough to go for latter.
From a pure brand perspective, the smart move for Microsoft would be to stop selling windows home.
I think MS-software to be less attractive than any time before. Be that windows, their office suite or their cloud landscape, which mainly excels at being slow. And stronger competitors are not the reason for decisions that are mostly not consumer oriented.
While they sell this as something that protects against downloaded malware, I think this is going to be used a lot in software testing. We have lots of manual tests of desktop software that neads clean environments which is painful when e.g. comparing several versions side by side etc. This is great compared to running multiple full VM's side by side.
It's not helping against the notion that Windows is insecure to use...
What's your point? How is that not a reasonable business model?
"My spreadsheet won't open" 'don't use sandbox for that' "But you said every file I downloaded" 'no, only exe'
"I opened the PDF exe, edited it, now it's gone" 'self-extracting zips from our payroll system are fine'
Swing and a miss. It's interesting how Microsoft will force their slow AV onto every win10 home edition device, yet won't give actual tools users can protect themselves with.
https://cloudblogs.microsoft.com/microsoftsecure/2018/10/26/...
Exactly that.
Seriously, AV is pointless software. It will false-positive often, it will false-negative slightly less often, and it will introduce a performance degradation 100% of the time regardless. It is a bad solution to the problem of malware.
Folks who don't mind Windows S would already be using android/ios.
[1] I don't recall if S Mode currently allows sideloading non-Store but code-signed APPX/MSIX packages. I think it is supposed to? But I think my confusion is that it may differ (at least currently) between Windows Home in S Mode and Windows Enterprise in S Mode.
I've been wondering for a while what was preventing a virtual machine editor to step ahead in integration and let you run the hosts' applications in a safe, virtualized environment - I've had thoughts mixing a sort of overlayfs (no idea if that exists on Windows), RAM isolation, and chroot-like (again, no idea if that exists on Windows but there must be something similar, right?)
Anyway, I'm really happy to see Microsoft stepping ahead. Most programs downloaded online are simply unsafe - sometimes just for privacy reasons! - and I often don't feel comfortable running them on my bare metal OS (not even talking of cracked software).
When I first got back on using Windows after a long time on OSX then Linux (I'm not happy with recent Apple hardware, I'm missing a whole lot of entertainment/creation applications on Linux), I assumed Hyper-V would be the best option to have a reliable, built-in hypervisor on my system. I was wrong. My goal was to setup 2 VMs: Linux CLI only do development, Windows 10 for untrusted software. It worked but the graphics integration of the windows VM sucked, and the Linux VM was extremely unreliable - I can't recall exactly what happened but crashes were common, especially in situations like sleep resume, drivers updates etc.
I would like to finish this informative comment with a hope that this new "sandbox" feature fixes most of the problems I used to experience with hyper-V. I would also love to see the others - VMware and virtualbox - to implement such feature. Hopefully, this could bump the use of virtual machines at a personal level (agreeing on dman comment to, please!, make it a standard feature) and see better performances and painless integration in the future.
I haven't seen a single amd64 machine without a virtualization option (except Macs, which don't have a Setup menu in the firmware, but they have virtualization always enabled)
If not yet, then Windows Sandbox it is a less useful feature that it may seem, because we have to choose between Windows Virtualization and VirtualBox VM snapshots all the time.
First thought: I'd love to be able to ship an app w/ this enabled by default (i.e. it's an ephemeral app w/ no local data storage).
Second thought: I'd love to pause this snapshot and resume it. Too many apps store preferences that you don't want to reconfigure just because you want isolation from the rest of the system each execution.
Third thought: Instead of always-dispose-on-app-close, I would like to namespace/cgroups-style it instead. This is how I would expect the Chrome equivalent of FF's "containers" would be built (I know I can --user-data-dir which is similar).
> Our solution is to construct what we refer to as “dynamic base image”: an operating system image that has clean copies of files that can change, but links to files that cannot change that are in the Windows image that already exists on the host. The majority of the files are links (immutable files) and that's why the small size (~100MB) for a full operating system.
Does WMMD 2.5 require drivers to implement SR-IOV capability for GPU? Or does Microsoft used some architecture similar to mediated device in VFIO?
https://techcommunity.microsoft.com/t5/Windows-Kernel-Intern...
I'm not going to try to parse and decode that, but it's mostly unnecessary and my security software thinks it's an XSS attack (a false positive, I would guess). This link works:
https://techcommunity.microsoft.com/t5/Windows-Kernel-Intern...
Now we need the same for Android and iPhone, so we can run our apps in true isolation. I dont want apps to be anywhere near my actual data and contact information on the phone. Just mimic some fake contacts or whatever for majority of apps.
I'll admit that with a triple-monitor setup, I've sometimes wanted to remote in with only a dual-screen setup. So it wasn't perfect for me. It certainly did fine for my 95% use-cases. Having to reconnect to adjust desktop size just was never a big deal for me.
Maybe adjusting sizes is more of an issue for people today. If I was using a laptop and constantly docking/disconnecting external monitors with a large number of active connections, it'd annoy me to have to completely reconnect each time.
Anyway, I eventually switched for docker support, and used this powershell-based tool that converts VMWare workstation VMs to Hyper-V VMs - https://www.microsoft.com/en-us/download/details.aspx?id=424...
But maybe it’ll work with 1809, who knows. Don’t have it yet.
This item on their "Quick Start Guide" doesn't fill me with confidence.
Any takers on how long before an escape is disclosed? I think within 30-60 days.
Actually, what I do want to do more than anything in this sphere is run browsers in a VM. The account containers in firefox is not enough.
This would work without performance penalty if you could chroot jail a gui application. There's almost no overhead in a jail - it's not a full blown VM, just a different chroot.
Here is the best recipe so far:
https://news.ycombinator.com/item?id=14243672
... but of course that's not a fit for OSX, which has no Xserver and blah blah quartz blah blah major spaghetti to get that working. Also OSX does not have 'jail'.
Performance is a non-issue for me, generally the browser performance is limited by pages waiting for ad networks to serve up ads. A pi-hole helps (and running in a VM/Sandbox lets you run the filtering DNS server as a local process pretty easily.
Lack of local data persistence is similarly a non-issue as the reason for running this way is to drop tracking cookies etc that fall out of a browsing session like leaves on an autumn day.
If it had some built in way to defeat the dozen other ways in which a browser can be fingerprinted, then it would be perfect.
Just a simple way to avoid the ad trackers and keep my actual stuff safe from the evil doers on the web.
That may be exactly what you want, but it might come as a rude surprise otherwise.
Are there any good alternatives, that do support persistence ?
If you run an older/cheaper version of windows, I can recommend:
> In other words, the same executable pages of ntdll, are mapped into the sandbox as that on the host.
> We take care to ensure this done in a secure manner and no secrets are shared.
I would really like to see that last point elaborated. They claim it's completely separated from the host, yet they say it maps to the same physical memory, yet somehow it's done securely.
It's actually been integrated into Windows 10 Enterprise edition for quite a while now, and I personally use it to package up a lot of the apps I use on a daily basis, delivering the packages through a network drive and synchronizing the centralized state store with Syncthing for mostly seamless cross-device roaming. (You can download the App-V Sequencer from the Windows 10 ADK to package some apps to try it out for yourself, if you happen to have a copy of Windows 10 Enterprise: https://docs.microsoft.com/en-us/windows-hardware/get-starte...)
This actually works fairly well for most apps, but unfortunately the isolation isn't perfect, and some apps for inexplicable reasons manage to get around the App-V sandbox and read/write to the local filesystem directly (Especially apps that have some kind of licensing mechanism, where licensing state can't be properly isolated and synchronized. Though you could definitely argue that's the licensing mechanism working as intended, in my view it still represents a technical failure on the part of the sandbox that this can happen), forcing me to install them locally instead of keeping them as isolated App-V packages.
I was hoping this would basically be App-V but with better isolation through the lightweight virtualization layer they built for windows containers (and with less restrictive licensing. Seeing lots of valid criticism on licensing here, but from where I stand, Pro and above is still much more accessible than App-V's Enterprise-only), but looks like they can't quite serve the same use cases just yet.
App-V isolates state changes, but those isolated state changes are persisted on disk, so when properly configured, you can use an app across multiple sessions, closing and reopening at will without losing state, as if it was locally installed.
Sandbox also isolates state changes, but those state changes seem to be ephemeral and will be discarded upon closing the app. This means it's only useful for running apps that are mostly stateless or for experimenting with untrusted apps. There's nothing wrong with serving those use cases, but to someone who's been feeling the pain from App-V's poor isolation, and someone who's been watching immutable application ecosystems like Nix, Guix, Flatpak, Snaps, etc, flourish in the Linux world, it does seem like a missed opportunity. Definitely hoping they're planning to extend it to also support the same use cases as App-V in the future.
The current execution is nuts and doesn’t make any sense.
That’s a nice win for AMD at the expense of intel if true for corporate environments.
You could achieve all of this yourself manually and you still wouldn't call it a sandbox, you would call it VM.
A proper sandbox would be if you could run a program in the same operating system with an isolated execution environment, similar to how sandboxie does it.