Apparmor, Chromium sandbox, Firejail - which to combine?

Discussion in 'all things UNIX' started by rm22, Mar 4, 2016.

  1. MisterB

    MisterB Registered Member

    Joined:
    May 31, 2013
    Posts:
    1,267
    Location:
    Southern Rocky Mountains USA
    No, I'm just using it in real basic fashion with mostly default config files and no need for a password. It came with profiles for Firefox, Opera and Chromium and I haven't changed them. I added profiles for Seamonkey and Vivaldi. Seamonkey worked with the default configuration but it took some tweaking to get Vivaldi to work.
     
  2. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,199
    netblue30 answered a question here:
    This suggests that the privileges of the sandboxed application are immediately dropped after window creation (which you can easily confirm yourself with ps aux). This is exactly what our friend Hungry Man requested in his blog post about the chroot sandbox.

    Further measures are implemented. In a thread regarding a profile for Skype netblue30 wrote:
    I hope that above remarks answer your question.

    FWIW, there is a positive review on the website for Linux professionals, lwn.net. They wrote:
     
  3. AutoCascade

    AutoCascade Registered Member

    Joined:
    Feb 16, 2014
    Posts:
    741
    Location:
    United States
    Yes thanks summerheat! Firejail is stronger than I thought.

    I know its being placed into some repositories such as Gentoo that really raised my eyebrows (not an easy task) when I saw it.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.