Replies: 3 comments 19 replies
-
If you want to sandbox servers (e.g. dnsmasq, unbound, nextcloud, nginx, ...) just use systemd's native sandboxing features. Or you use SELinux (RHEL) or AppArmor (Debian/Ubuntu/SLE).
Related: #3412 (comment)
TBH: I'm working on something but don't expect an alpha before 2022 if at all. And to mention it, there is bubblejail. |
Beta Was this translation helpful? Give feedback.
-
MY OPINION! only against direct usage of bwrap:
Give me the next days and I come up with a bigger writing. |
Beta Was this translation helpful? Give feedback.
-
I think madaidan's recommendations are quite problematic. He recommends MacOS, windows, and iOS over linux. MacOS, windows, and iOS don't respect privacy and freedom. The strongest security doesn't matter if it comes without freedom and privacy. There should be balance. |
Beta Was this translation helpful? Give feedback.
-
In 2019, madaidan criticized firejail from the perspective of security and attack surface. However, security is not independent of all other qualities. Security without freedom and privacy is pointless and can easily turn into another tool of control by government and big tech(e.g., secure boot, CPU management engine, proprietary trusted exeuciton environment(TEE), location tracking by "secure" smartphones, ...). Security should serve privacy and freedom.
In theory, firejail offers less security than bubblewrap by exposing a much bigger attack surface in one binary. However, if you take privacy into account, firejail starts winning.
Until a versatile bubblewrap frontend or a better sandboxing platform appears, I think firejail is the best there is for linux desktop computers. I think enterprise servers that don't need to run a lot of applications or don't need firejail's functionalities can be better served by bubblewrap. Even political dissidents can benefit from firejail when they don't want to use whonix or qubes OS.
But, firejail should improve security by delegating privileged operations to small binaries.
Beta Was this translation helpful? Give feedback.
All reactions