Firejail or Snap?

Discussion in 'all things UNIX' started by shmu26, Jun 10, 2022.

  1. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,550
    If I want to up my security on linux by running Firefox and Thunderbird in a sandboxed environment, which is better: Firejail or Snap apps? Or maybe Flatpaks?
    Which is more likely to give me headaches?
    And maybe all this is totally unnecessary, because who ever heard of zero-day exploits on Firefox or Thunderbird running on linux?
    I usually run Manjaro Gnome or Kubuntu.
     
  2. nicolaasjan

    nicolaasjan Registered Member

    Joined:
    Sep 23, 2018
    Posts:
    890
    Location:
    The Netherlands
    Very unlikely that zero-day exploits are used against ordinary people. :)
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,066
    Location:
    Canada
    I've ran browsers and Thunderbird in Firejail with no issues whatsoever. As for Snap apps or Flatpacks, I've no idea.
     
  4. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    Use a Thunderbird hardening.
     
  5. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    Personally I think that browser should be first-and-foremost up-to-date. Even if you manage to contain infection to the space Firefox is using it is still quite a lot of valuable data here (cookies, some passwords, etc). And there are some attack that do not intend to get into system - they just want to inject some frame on site that should eavesdrop on typed keys that potentially contain user data, passwords, card numbers etc.
    Debian wasn't really keeping browser up to date as fast as I would like so I chosen Snaps. Flatpak probably would also be ok, or even better privacy wise.
     
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Use Firejail and/or AppArmor(I think they can be combined) for sandboxing and restricting rights. Snap and Flatpak are a different software distribution method, not a security solution. They do offer some sandboxing functionality, but it is up to the developer of the application to add sandboxing rules, a lot of applications are not sandboxed at all.(Even though they may have a misleading Sandboxed icon, that does not give any guarantees, at least for Flatpak, I have no experience with Snap.)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.