Sandboxed applications for Gnome, part 2
blogs.gnome.org
blogs.gnome.org
I think this is absolutely a wonderful idea in general and needs to happen soon. Once any program a Linux user is running is compromised, essentially the whole machine is compromised. This is quite unfortunate.
My main complaint is the file chooser dialog. I would much rather see a traditional file chooser - the arguments given for reinventing it don't hold up. You can pass file descriptors between processes. If you want to select a "cloud file", use fuse with some pretty integration, which is just how GNOME 3 does it right now.
I have only the most general of ideas of what my computer is doing at any one time. I know that the software I was using one year ago was riddled with vulnerabilities that were undetected at the time. It seems foolish to assume that the software I'm using now doesn't have similar issues.
I personally welcome anything that lowers my security risk. Sandboxing applications seems a fantastic idea, if it can be done without unduly affecting my workflow.
It's just like a car. You don't have to know how your car's engine works to be able to tell tell when your car isn't running like it's supposed to. As for my computer, I know it in as much detail as I think is necessary for telling whether or not the computer is "healthy", so yes. (See my response to the other comment for more.)
Security isn't an absolute; it's just a matter of how much risk you're willing to allow for convenience. Ideally you make it hard enough to compromise your machine that an attacker won't bother.
Yours can too. How do you know yours isn't?
Yeah then why do you suddenly jump when I tell you the same thing? To the best of my knowledge I don't have any malware, and to the best of your knowledge you don't either. Seems pretty equal to me, yet somehow you freak out when I say the same thing as you do. I'm pretty sure I'm at least as certain as you are that my system doesn't have any malware, so if that's not enough of an assurance for you then it shouldn't be enough for you either.
> Absolutely horrible idea. Linux users aren't exactly in desperate need of protection from their computers.
If you agree that your system can be compromised, why would you say that an extra layer of protection was a bad idea?
But even if all previous efforts have failed, which I really don't think is the case, trying to improve security is surely a laudable goal. And even if you would consider sandboxing to be inconvenient, there are plenty of people who'd love to have something like that.
Right now, if I open up an application, I have no idea what directories it's accessing or servers its communicating with. Forcing an app to tell me whenever it wants to access something new would be fantastic, and as a side effect, it would put pressure on application programmers to reduce the number of privileges they ask for.
And how do you know you have not got malware in years? Not all malware are of the flashy "pop up ads in front of you" nature. Running as root 24/7 is a ridiculously stupid idea, especially for a desktop, no matter how careful you are.
Same way you can tell whether you're feeling healthy or sick.
Same way you "know" something is wrong when your car stops running the same way it usually does.
i.e., I can't prove it one way or another, but that doesn't matter. In practice, I mentally keep a tab on how my computer is running -- my computer's CPU usage, network activity, I/O activity, internet connection speed, etc. so I can tell when something's not going right. I don't keep crapware on my computer either, so when a process shows up that I don't recognize, then I can easily tell. I have notifications set up for newly-installed system services, so when a new service or driver is installed I get a popup for that too.
Obviously, I can't prove it's malware-free, but who cares? I don't need to. I simply have no evidence in support of malware existing on my computer, so as far as I'm concerned, it isn't. Just like you can't mathematically prove to me that your car is OK, I can't mathematically prove to you that my computer is running OK. But that doesn't matter because I'm reasonably sure it is, and I have no evidence to believe otherwise. And that's really all that matters.
And for that matter, it's not like I could be sure I didn't have malware if I did follow those practice either. It's just a tradeoff between the likelihood of malware and the amount of convenience you're willing to give up. You can never be sure, and you don't need to.
And, no offense, but seeing your judgement regarding root and you actually thinking that sandboxing is a terrible idea because "you know better", well... I wouldn't touch your judgement with a 3 meter stick, be it on feeling healthy or on your computer running malware.