Related: could we please stop, by default, allowing software to:
a) access all your files, and
b) roam the internet at will.
That was somewhat OK in the 80s, but it hasn't been since.Related: could we please stop, by default, allowing software to:
a) access all your files, and
b) roam the internet at will.
That was somewhat OK in the 80s, but it hasn't been since.
I wouldn't mind, but there needs to be a way to remove the "training wheels".
I don't want my computer to always be as closed and restrictive as an iPhone. That's good sometimes and perfect for some users, but not for everyone or all the time.
Ironically, the closed and restrictive iOS and Android go then out of their way to make restricting Internet access hard
Hard for you to restrict access of third parties. Easy for you to restrict your own.
That would make all the spying and surveillance harder and thereby reduce profits. And profit reduction is really the worst attack risk of all.
Of course, I was just saying "by default". You should be able to allow any access as you want, give it your old socks or granny. Just not by default.
These days, most things that I run that aren't from my distro's repos get their own bubblewrap. On top of this, I use opensnitch. Even if I trust the application (uncommon), I never trust npm, pypi, etc. any longer. It's tedious to set this up and OSes should be helping make this easy.
Agreed. Programs like Zoom, Steam, and other closed source "apps" should always run either in a separate user account or in a bubblewrap.
The problem is, peoples files are too valuable - even to the OS vendors - and also, there are simply too many valuable people on the Internet without the willpower to know how to manage their own filesystem.
If the OS vendors are motivated to harvest peoples data, why on Earth would they be motivated to make sure nobody can harvest peoples data?
I am in agreement. I am always curious as to the solution because VMs are not the solution and zero knowledge is helpful but not quite there.
VMs can help a lot, see what Qubes OS does
In 2026, we still don't have a major OS that sandboxes everything.
Googlebooks, which start shipping this month, will run a fork of Android 17, which sandboxes every app.
Also, some people use an iPad Pro connected to a USB hub connected to a monitor, keyboard, etc, as their daily driver.
Also, doesn't MacOS sandbox most apps?
macOS does it pretty well, right ?
Among the old school desktop OSes it's one of the better options, but it still has a long way to go compared to mobile OSes.
Half the problem is that too many people rely on commercial software that will crap itself if it doesn't have access to what it wants whenever it wants. If, say, Adobe CC stops working after a new macOS release because macOS won't allow it to litter the filesystem any more, the one taking the heat won't be Adobe (which shouldn't have been doing that in the first place) but rather Apple.
Yes, this is exactly how Qubes OS works.
Not if I have anything to say about it. I want programs on my computing device to be able to access files and roam the internet at free will. In fact, I insist on it.
Agreed. I mean, AppArmor and SELinux exist to control file access, perhaps OSes should put more effort into user-friendly overlays to control processes and have audits to warn users when a piece of software has full system access.
As far as network control... We have open-source blacklists for various malicious websites. Perhaps we should also have "known-good" site whitelists and have OS-level blocking for that by default. Like, OSes running DNS-sinkholing of StevenBlack malware lists, and the option to enable "known-good" whitelists as well. Having a hosts file of 450,000 entries to sinkhole can bog down an interface coming up reliably... that process needs optimized.
There's a lot of money in the enterprise world doing similar things.
[dead]