Private Home Directories for Ubuntu 21.04
ubuntu.com
ubuntu.com
Most of my systems have a user for myself, and one or two other users like `sketchy` or `test` or something for programs that I trust enough to run, but don't trust enough to not fuck up my home directory in some way (including modifying startup scripts, which IMHO should probably require sudo to edit, even for a normal user).
If the program is really sketchy and you're worried about it doing something like exfiltrating ~/Documents/taxes, then private home directories would definitely seem like a good default. You can always have an explicitly shared area like /home/shared/$user that defaults to public.
That's why I think intra-user isolation is better. I would feel so much better if my browser could just access its settings, the download directory, and read access outside my home directory (for libs and such).
The tricky part are the profiles afaik. But this could be solved with some concentrated community effort I guess.
I think AppArmor does something similar (I don't know the differences to SELinux in detail, so if someone like to clarify please go ahead). I remember I've seen some AppArmor related stuff regarding Firefox (and LibreOffice I think) in Ubuntu. So seems not much is missing to have at least an sandboxed web browser out-of-the-box on a Linux desktop.
Profiles are indeed tricky though, and generally something I would consider more easily implemented as just logging in as a different user.
I can't speak much about AppArmor since I'm not too familiar with it.
You could probably use Qubes OS instead.
It's been a while, though. But now I'm also spoiled with Sway. Haven't checked if I can keep Sway on qubes.
I regularly have to both download files to other directories than my Download folder and upload files from other directories, such a restriction would break a lot of existing use cases.
The optimal way to achieve this would be to have the file / save picker a completely separate process, which then passes a token to the browser, which the browser then exchanges at some sort of "broker" process that returns a handle to the file.
sudo flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo
sudo flatpak install -y flathub org.chromium.Chromium
sudo flatpak override org.chromium.Chromium --nofilesystem=home --filesystem=$HOME/DownloadsSo, finally I learned just not to use file-based encryption, except for minor stuff like dropbox directory.
EDIT: Looks like LUKS is supported now, which is nice:
https://wiki.archlinux.org/index.php/Systemd-homed#LUKS_home...
You need either full disk encryption, or something like dm-verity for that.
1. Create a file in your home called .hidden with one line "snap" to hide it in the file browser.
2. You can add --hide=snap to your ls alias to hide folders by that name.
https://bugs.launchpad.net/ubuntu/+source/adduser/+bug/48734
I also created eCryptfs, which was Ubuntu's original home directory encryption technology, with lots of additional distro integration work by Dustin Kirkland. Unfortunately I had to make some compromises when going with the stackable model, and that caused some problems.
I took the lessons I learned from that first attempt and created fs-crypt as a sort of atonement. I think I got a lot more right on my second attempt at file-base encryption in Linux. At least, it's good enough to be the technology that now encrypts Android storage.
The problem with Linux supporting stuff forever is that some things really need to be retired once a better solution has come along. However so long as there are eCryptfs users out there, I don't think it's going to ever go away at this point.
In some ways, encrypting the entire disk is more secure.
https://talldanestale.dk/2020/04/06/zfs-and-homedir-encrypti...
Hope general zfs support will improve in the installer, though. As well as automation and tooling around automatic snapshots.
$ dpkg -S /etc/login.defs
login: /etc/login.defs
https://packages.ubuntu.com/login -> hirsuite -> changelog gets you to https://changelogs.ubuntu.com/changelogs/pool/main/s/shadow/... where you can see this is an ubuntu-specific patch introduced in version 1:4.8.1-1ubuntu8If the attacker can already access arbitrary files on your box, I don't think simple unix permissions will save you
chmod'ing the homedir would've prevented that. Unix happens to be pretty good about directory permissions.
Welp. Yes, I misremembered that specific example.
Still, you’d be amazed how often people leave json credentials in their homedir that can be used to pivot to e.g. S3.
Another reason I don’t sudo and instead ssh
All sorts of horrible side effects can immediately be identified.
Then again checks foil hat, that’s what you want us to believe ;)
Because small increased of privacy should not result in huge usability decrease.