Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cool profiles #18

Open
3 of 6 tasks
nyancat18 opened this issue Apr 12, 2017 · 7 comments
Open
3 of 6 tasks

cool profiles #18

nyancat18 opened this issue Apr 12, 2017 · 7 comments
Assignees

Comments

@nyancat18
Copy link

nyancat18 commented Apr 12, 2017

  • openvpn
  • eddie (for airvpn...A VERY COOL vpn but premium),
  • i2p (taking as base the i2prouter with systemd services installed at /opt)
  • freenet
  • dia (ms visio like)
  • geany (a COOL IDE)
@chiraag-nataraj
Copy link
Owner

Added Dia! 😄

@chiraag-nataraj
Copy link
Owner

With respect to geany, won't the profile depend on which plugins you need? Like, if you're never going to use the C stuff, then giving geany access to gcc is a terrible idea.

@chiraag-nataraj
Copy link
Owner

@nyancat18 What level of security would you like for geany? That is, what exactly do you use it for? Because that will definitely determine how restricted the profile is. I can also completely leave off private-bin, but that's not exactly that secure...

@chiraag-nataraj
Copy link
Owner

I would recommend that you use systemd to sandbox system services like openvpn (and related VPN services), i2p, and freenet. You get the same granularity as with firejail (sometimes more), and with system services, you get the full range of options systemd has to offer (unlike with user services, where firejail is really useful).

@chiraag-nataraj
Copy link
Owner

I'll try to bring in a profile for geany though.

@chiraag-nataraj chiraag-nataraj self-assigned this Jul 21, 2018
@chiraag-nataraj
Copy link
Owner

Done!

@chiraag-nataraj
Copy link
Owner

After reconsidering, I'll try to bring in a profile for openvpn, i2p, and freenet. Since I don't have AirVPN, I can't test eddie at all, but if you want to bring in a profile for that, I'd be happy to merge it. Re-opening as a result.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants