Walsh: Cool things with SELinux... Introducing sandbox -X
Walsh: Cool things with SELinux... Introducing sandbox -X
Posted Sep 18, 2009 0:00 UTC (Fri) by martinfick (subscriber, #4455)In reply to: Walsh: Cool things with SELinux... Introducing sandbox -X by martinfick
Parent article: Walsh: Cool things with SELinux... Introducing sandbox -X
But, distributions typically stop at sandboxing servers, why? Because to manage sandboxing you need root priviliges! Distributions do not typically sandbox human-user apps (desktop apps) because most human users do not have the privileges on a machine to create the necessary bridges between their apps if they were sandboxed. Human users really need "root level" control of their own domain to ever make sandboxing of applications manageable; no distribution can anticipate all the bridges between user applications that might need to be created. Thus, the need for a separate container for each human user, to give human users "root" privileges without compromising the host or other human users.
