Skip to content

What would be THE answer to non-VM compartmentalization-based desktop linux security ? #50

Closed Answered by igo95862
planetoryd asked this question in Q&A
Discussion options

You must be logged in to vote

From the looks of it opensnitch is a firewall application that does not actually provide the file system sandboxing.

bubblewrap currently doesn't support Netns

It does in a sense that it can create a new network namespace for sandbox. However, it does not provide any tools to work with new namespace. You can use tools like slirp4netns to create networking for the new namespace. Bubblejail has a service that can use slirp4netns to create separated networking in sandbox.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@planetoryd
Comment options

Answer selected by igo95862
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants