←back to thread

441 points longcat | 1 comments | | HN request time: 0.23s | source
Show context
vorgol ◴[] No.45039050[source]
OSs need to stop letting applications have a free reign of all the files on the file system by default. Some apps come with apparmor/selinux profiles and firejail is also a solution. But the UX needs to change.
replies(5): >>45039375 #>>45040698 #>>45041459 #>>45041809 #>>45045968 #
terminalbraid ◴[] No.45039375[source]
Which operating system lets an application have "free reign of all the files on the file system by default"? Neither Linux, nor any BSD, nor MacOS, nor Windows does. For any of those I'd have to do something deliberately unsafe such as running it as a privileged account (which is not the "default").
replies(6): >>45039776 #>>45039798 #>>45039824 #>>45040322 #>>45040368 #>>45040974 #
sneak ◴[] No.45039776[source]
https://www.xkcd.com/1200/

All except macOS let anything running as your uid read and write all of your user’s files.

This is how ransomware works.

replies(1): >>45040144 #
1. fsflover ◴[] No.45040144[source]
You forgot the actually secure option: https://qubes-os.org