Kevin Karhan :verified: · @kkarhan
1416 followers · 100300 posts · Server mstdn.social

@da_667 You don't - you just a physical machine if not entire network the same way actual analysis and benchmarkers do.

In fact tools like exist that detect and and then either suicide the malware or just refuse to run entirely to twart forensics experts to the point that there's no off-the-shelf solution to do so.

#virtualization #sandboxing #imvirt #antivirus #Malware #airgap

Last updated 1 year ago

SPdeValk 🐘️ ☑️ · @sjosjo
43 followers · 144 posts · Server mas.to

The cloud posture is in rapid decline ever since the Solar Winds disaster.

When one of the most popular IDEs ever, , has a token strategy that is laughable, you know things will only get worse.

I understand is difficult, but doing absolutely nothing and let wreak havoc indiscriminately is just plain

bleepingcomputer.com/news/secu

#securitybydesign #GoodGovernance #negligence #extensions #sandboxing #encryption #vscode #security #Microsoft

Last updated 1 year ago

silifi and/or queso · @silifianqueso
39 followers · 36 posts · Server dice.camp
Kevin Karhan :verified: · @kkarhan
1248 followers · 81861 posts · Server mstdn.social

@Seirdy *nodds in agreement*

was necessary and so far I think it did solve a lot of issues. OFC for embedded Systems one can still literally use a single shell script as init process...

is a feature and Tools like , and make it easy to provide cross-distro apps that just run.

Verified Bootchains as implemented with on are just bad . as alternative Firmware makes it better.

#heads #DRM #uefi #CensorBoot #appimage #Flatpak #snap #Security #sandboxing #systemd

Last updated 1 year ago

NastyBigPointyTeeth!🌈♀ · @MsDropbear
209 followers · 1180 posts · Server kolektiva.social

@TiffyBelle @flaminghohners T/y. That was an interesting read, & ostensibly disturbing. Ostensibly.

My geeky-user-but-NO-expert familiarity with [, specifically] & chromium-based browsers [on my ( only) pc's that's & ] extends to matters of features, functions & privacy. Security, in the context of that paper & its links, is way beyond my knowledge, so it'd be silly of me to attempt any technical disparagement of that paper.

I shall note, though, that browser development is a pretty fast-paced project, such that i do wonder about the contemporary validity of any paper written several years ago. The paper was last edited March 19th, 2022, so clearly not too bad. However, & IMO most unfortunately, ALL its purportedly supportive links to external references are VERY old, ranging from newest of 2020, to oldest of 2011, with a perceived median around 2016.

For instance, the linked paper's linked paper "Exploiting and Protecting Dynamic Code Generation", says on p10, within "A. Setup", that

>The operating system is the 64-bit Ubuntu 13.04 with kernel 3.8.0-35-generic

That version was released in early 2013.

I suspect this potential "technological aging" makes many or maybe most of the underlying claims rather dubious today, unless & until a contemporary reappraisal by technically competent peeps were done, based on current code, not on how it used to be many years ago. Maybe the conclusion would not change? Maybe it would? 🤷‍♀️

Other Thoughts, fwiw.

Even with a generous assumption that all claims in that paper remain technically valid today [tbc], for many browser users in countries / jurisdictions not overtly fascist & dictatorial, who as individuals are unlikely to be targeted by state-actors, i respectively opine that the larger more probable safety hazard to them might come from , not , breaches. To that extent, i note these:

- is more powerful in Firefox than in chromium browsers, due to the latter having no support for CNAME-uncloaking

- Google is actively striving, via its Mv3 replacement for Mv2, & its egregious FLoC / Topics crap, to further weaken uBO & all other . Otoh, Mozilla intends indefinite Firefox support for Mv2, albeit also with added Mv3 compatibility.

-- / like are far more than "only" adblockers. By running in "hard mode" for instance, & liberally creating a suite of global & per-site dynamic filters, AND having globally disabled but allowed by the user on favoured sites, great privacy protection is afforded. Google's plans are to actively weaken this user privacy in Chromium.

- sadly, silly insecure-by-design MS Windows remains the world's dominant OS. Yet for those alert to the Windows hazards & willing to make a change, provides vastly more security & privacy by design.

- As well, both dominant & at least one , now provide stable everyday capability instead of the ancient insecure / -- thus eliminating one classic security vulnerability mentioned in the paper/s.

- Linux users can avail themselves of even more privacy by their apps. There's several choices; i use . Therefore browsers [& all other relevant apps] cannot access any of the user's private data beyond the sandbox's bounds.

#firefox #nightly #Linux #vivaldisnapshot #chromium #privacy #security #ublockorigin #adblockers #addons #extensions #ubo #javascript #desktopenvironments #windowmanager #wayland #x11 #xorg #displayserver #sandboxing #firejail

Last updated 1 year ago

Kevin Karhan :verified: · @kkarhan
813 followers · 40570 posts · Server mstdn.social

@mikeylikestech @nixCraft @fuchsiii and also do it with because a lot of badly-coded games are notorious for and forcing said wine apps into sandboxes is mitigates security risks of shitty apps...

mstdn.social/@fuchsiii@oxytodo

#win32 #memoryleaks #sandboxing

Last updated 1 year ago

CK's Technology News · @CKsTechNews
1961 followers · 5760 posts · Server cktn.todon.de
Alexandra :vinyl: · @sgirlprivacy
625 followers · 395 posts · Server universeodon.com

Some question, do you know :

1 how to use bwrap for Xwayland app ?

I try to use some python app who have a gui inside it, and i always finish with :

Authorization required, but no authorization protocol specified

and the prython library of course generate the error:
No available video device

the 2 Display command used on bwrap :

--bind /tmp/.X11-unix/X0 /tmp/.X11-unix/X0
--setenv DISPLAY :0

(have also tried with X1 and another number used by gdm).

It seem i've missed something, and there is no Xauthority file into my home, so i cannot bind it (like some older forum tell).

If anyone can point out what i do miss.

#bubblewrap #bwrap #xwayland #wayland #silverblue #sandboxing

Last updated 1 year ago

CK's Technology News · @CKsTechNews
1929 followers · 4802 posts · Server cktn.todon.de
CK's Technology News · @CKsTechNews
1893 followers · 4065 posts · Server cktn.todon.de
Linux ✅ · @Linux
4811 followers · 2930 posts · Server linuxrocks.online

::: Licks from FOSDEM '23 - "I was wrong about Snaps and Flatpaks"

With Snaps / Flatpaks, one can use older distros to build software for old OR new distros with no issue.

Both Flatpak / Snap build tools are nice for developers. No need to package to 10 distros (and manage them) no more either.

Then there's sandboxing. Canonical has said they'll open the Snap Store backend, too, later on. As they did with Launchpad.

How opinions change as things progress, here's to that.

Richard Brown => ftp.fau.de/fosdem/2023/UA2.114

#software #developers #sandboxing #flatpak #snap #packaging #linux #fosdem

Last updated 2 years ago

Bienenjörg · @bienenjoerg
8 followers · 522 posts · Server aipi.social

@derAlff_iot ich weiß nicht. Ich hab mir bisher nur angeguckt, was das Upgrade an Neuem mitbringt - im Wesentlichen .

Wenn die Entwickler sich langweilen, könnten sie doch mal anfangen, eine gescheite umzusetzen - z.B. , , wie es vormacht.

Für ein bisschen Kosmetik ein ziehen, nee, das ist mir z.Zt. zu aufwendig.


#LookAndFeel #Sicherheitsarchtektur #sandboxing #SafeBoot #android #upgrade #linux #linuxmint

Last updated 2 years ago

jbz · @jbzfn
255 followers · 1768 posts · Server mastodon.social

「 Additionally, writing parts in a memory safe language does not necessarily improve security and may even degrade security by allowing for bypasses of exploit mitigations.

Some security features are geared towards a particular language, and in an environment where different languages are mixed, those features may be bypassed by abusing the other language 」





#firefox #chrome #vulnerabilityassesment #sandboxing #infosec #rustlang

Last updated 2 years ago

jbz · @jbzfn
255 followers · 1768 posts · Server mastodon.social

「 Firefox does have some parts written in Rust, a memory safe language, but the majority of the browser is still written in memory unsafe languages, and the parts that are memory safe do not include important attack surfaces, so this isn't anything substantial, and Chromium is working on switching to memory safe languages too 」





#firefox #chrome #vulnerabilityassesment #sandboxing #infosec #rustlang

Last updated 2 years ago

CK's Technology News · @CKsTechNews
1797 followers · 2669 posts · Server cktn.todon.de

Firefox 110.0 Beta 2 enables GPU on Windows only

mozilla.org/en-US/firefox/110.

#sandboxing

Last updated 2 years ago

· @psomas
51 followers · 21 posts · Server discuss.systems

Great talk by @qwertyoruiopz on iOS / MacOS / Darwin security and exploitation. youtube.com/watch?v=8mQAYeozl5 Really interesting from an OS / systems perspective, wrt to sandboxing. Stumbled upon it while reading about OpenBSD's new mimutable() syscall. lwn.net/Articles/915640/

#infosec #apple #sandboxing #os #systems

Last updated 2 years ago

M · @miguelHzBz
6 followers · 34 posts · Server mastodon.social

Hoy a las 17:00 doy la charla:
Reforzando la seguridad de Kubernetes con y en la Kubernetes Community Days Spain.

¿te apuntas? 👉🏼 buff.ly/3sFRqdx

#gvisor #falco #cloudnative #sandboxing

Last updated 2 years ago

Swapnil · @thinkfree
47 followers · 141 posts · Server fosstodon.org
(RTP):tor:Privacy & Tech Tips · @RTP
2615 followers · 3880 posts · Server fosstodon.org
(RTP):tor:Privacy & Tech Tips · @RTP
2615 followers · 3880 posts · Server fosstodon.org

:tor: Tor Browser User Deanonymization Example: careful downloading files + Easy GUI Sandboxing Solutions Featuring Firetools, Flatpaks + Flatseal

(post now public)


buymeacoffee.com/politictech/d

#blog #sandboxing #firejail #flatpak #Flatseal #torbrowser #anonymity #privacy

Last updated 2 years ago