Sandboxie-Plus – a fork of Sandboxie with improved functionality
github.com
github.com
Finding leaked but operational EV code singing certs online should not be a thing ...
This seems fairly sane to me, and and allows doing things in software like trusting particular publishers.
What errors do you believe are silenced when an executable has an invalid or untrusted signature?
Similar thing for the script signing policies -- during my testing the default seems to want a signature, but not a valid chained one. I was confused in the same way you are, but the documentation doesn't actually say you need a valid chained signature nor does it really describe the threat and security models.
They just have signatures, because signatures make things more secure, right?
Paragraphs 1 & 2 do not go well together, and I will never use this product, despite my having tested sandboxie itself in the past.
Odd Story: The single person listed on the github page also has a fork of the original DiskCryptor code. At a prior employers I had worked, we once wanted to embedd DC into a larger framework. After some time we were able to find people to contact. They were using some elaborate scheme to hide their identities and yet converse over the phone. Since it was an "Open Source" project, and we already had the source code, we had reached out to them as a courtesy and nothing more. In fact we had already found serious bugs that we had fixed interally. Yet, they demanded an astronomically high sum for the use of DC. What did we do? The room of us laughed at the DC folks on speaker phone, then we went off and finished our own framework without using DC.
There is a small segment of people on the fringes of the security industry who work for a government (trying to get people to use their product), are running from a government, have stolen code from a government, are involved with shady business dealings, etc. It's best to stay as far away from these people as possible at all times. I'm not saying the person who started this github falls into that category, but it's best to think about that before using what is a security product.
It's similar to containers on Linux in that sense, it has little to no overhead (sandboxing games works great in most cases), but in an even more user-friendly package than something like Docker. Highly recommended.
How to Safely Run Software With Windows 10 Sandbox https://www.pcmag.com/how-to/how-to-safely-run-software-with...
Are there any reasons to use one over the other?
2. Everything gets wiped when you close a win10 sandbox (so installations can't survive beyond a login session). In Sandboxie you appear to get a copy of your existing OS, and the copy is only wiped when you choose to wipe it (so it can survive across login sessions). The win10 sandbox is wiped when you close it, and you have to close it to turn off the PC.
3. Win10 sandbox seems not to like making the camera or microphone available to apps (eg zoom, skype) whereas Sandboxie is happy with making them available.
4. Because of the above, win10 sandbox is probably more secure than sandboxie, but there is no indication of where the sandbox state was stored, so it isn't possible to secure delete it like you can with sandboxie.
I use this feature when I run Firefox in a Sandboxie sandbox while preserving it history and bookmarks. I find it pretty annoying to have those cleared whenever I delete my sandbox, so much prefer to have those saved.
It sounds like the win10 sandbox can't do this.
Sandboxie is super lightweight cupboard to that.
As per this[1] post, it's going to be a continuation of existing Sandboxie without major changes. And, it's going to have signed driver.
[1] https://www.wilderssecurity.com/threads/sandboxie-technologi...
Much the way people probably feel when iOS started showing clipboard access so you could physically see when apps were doing something invasive? That was the feeling I got constantly with every app and every invasive action when I was using Sandboxie. Truly a gem.
I had a surprising hard time to find an equivalent for linux. Today firejail fill that void pretty well.
b. What is the status of docker-on-windows? is it stable-but-slow or simply not ready yet ?
c. Why didnt Sandboxie become a multi-million-$ project? It was years ahead of docker, and there is a great need for it on Windows than Linux IMHO.
I wonder if this new incarnation of Sandboxie uses any of them.
https://geekermag.com/enable-windows-sandbox-in-windows-10-h...
They should give other kind of features and apps instead. Never negotiate security, and made it universal, giving more strength to their image.
Think of it, in the end you will be paying to be protected from the insecurity that is only there because of the flaws in their platform.
Its like a mob rising the crime levels on a neighborhood and at the same time asking to be payed to grant you security for the troubles people are only having because they are creating those same troubles in the first place (even if/when indirectly).
I never understood why you would have to pay for security... "Oh look, our software is inherently insecure, but if you pay more, you can get a mitigation." It truly gives no good light on whatever you sell.
Sandboxie was a big part of the original technology used by Invincea which was later aquired by Sophos.
If you're asking specifically about Windows containers though, I've never used them (few do, I think).
I've been thinking about giving it a stab myself, and I can't think of any obvious roadblocks.
Also a few solutions like Snap and Flatpak exist on Linux where the applications come pre-sandboxed. For Mac, the official Mac App Store's applications are all sandboxed also.
Which of them are widely used, as easy to use and as feature rich as Sandboxie, and are well maintained?