Unless something has changed, it's worse than that. Plugins have unrestricted access to any file on your machine.
When I brought this up in discord a while back they brushed it aside.
Unless something has changed, it's worse than that. Plugins have unrestricted access to any file on your machine.
When I brought this up in discord a while back they brushed it aside.
[1] https://docs.docker.com/desktop/settings-and-maintenance/set...
The first time I started installing flatpaks I ran into a bit of permission / device isolation trouble and ever since then, I use flatseal after installing an app to make sure it actually has access to things.
I guess I misremembered in the case of Obsidian.
It sounds like if I ever run obsidian I should be using flat seal too.
I'm not claiming it's a security feature of Obsidian, I'm saying it's a consequence of running a flatpak - and in this situation it could be advantageous for those interested.
There are so many options, from so many different security perspectives, that analysis paralysis is a real issue.
For user-space, there is usually bubblewrap vs. firejail. I have not personally used bubblewrap, so I cannot comment on that, but firejail is great at what it does.
The last comment was about restricting clipboard access to either X11 or Wayland which is possible with firejail quite easily, so if you want that, you can have that.
You can do a LOT more with firejail though.
In case anyone else is curious, I found the following comparison in bubblewrap's repo.
- https://github.com/containers/bubblewrap#related-project-com...
I'm gonna try both and see which one I like. Thanks for this info! You're sure living up to your user name there. (:
> You're sure living up to your user name there. (:
You are too kind, thank you!
This is my ~/.config/firejail/Discord.profile[1]:
include disable-common.inc
include disable-devel.inc
include disable-interpreters.inc
include disable-shell.inc
noblacklist /sys/fs
noblacklist /sys/module
keep-config-pulse
keep-dev-shm
name discord
apparmor
caps.drop all
caps.keep sys_admin,sys_chroot
netfilter
nodvd
#nogroups
#noinput
nonewprivs
noroot
notv
#nou2f
#novideo
protocol unix,inet,inet6
#shell none
disable-mnt
private-cache
#private-tmp
noexec /tmp
dbus-user filter
dbus-user.talk org.freedesktop.Notifications
private-bin Discord,cut,echo,egrep,electron,electron[0-9],electron[0-9][0-9],grep,head,sed,sh,tr,xdg-mime,xdg-open,zsh,gzip,wget,curl,notify-send
private-etc alternatives,asound.conf,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.preload,localtime,login.defs,machine-id,password,pki,pulse,resolv.conf,ssl
noblacklist /usr/lib/discord/
whitelist ${HOME}/.config/discord
read-write ${HOME}/.config/discord
whitelist ${DOWNLOADS}
whitelist ${HOME}/.config/pulse/*
include whitelist-common.inc
include whitelist-var-common.inc
include whitelist-run-common.inc
include whitelist-runuser-common.inc
I have some things commented out but you could probably uncomment most.Some has this, too:
disable-mnt
private-dev
private-cache
env http_proxy=socks5://127.0.0.1:9050
env https_proxy=socks5://127.0.0.1:9050
FWIW, once you start whitelisting, it will only have access to those directories and files only, so Discord has no access to anything other than its own directory and ${DOWNLOADS}, which I should probably change.You should check out the default profiles for many programs / apps under directory "/etc/firejail".
[1] You run it via "firejail Discord" or "firejail ./Discord" if you name it "Discord.profile".
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Obviously it can detect malware if there’s a connection to some weird site, but it’s more like a bonus than a reliable test.
If you need to block FS access, then per app containers or VMs are the way to go. The container/VM sandboxes your files, and Little Snitch can then manage externa connectivity (you might still want to allow connection to some legit domains—-but maybe not github.com as that can be use to upload your data. I meant something like updates.someapp.com)
I got lazy
Time to crank the paranoidmeter up again
ty
Seems a little excessive, but here we are.