Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

91–100 of 328 posts

Re: Windows Sandbox

#91
post #53

Earlier quoted context omitted.

Except Windows store apps are strictly worse than being able to run regular Windows software in a sandbox.

One of MSIX purposes is to package old style Windows software, your regular Windows software into Windows Store sandbox, hence why I mentioned it. It is an evolution of desktop bridge, appx and msi.

I stand corrected.

Re: Windows Sandbox

#92
post #66

Earlier quoted context omitted.

I believe it's because the virtualization support is only limited to those versions. I might be wrong though.

Isn’t this basically a virtual machine, though? I don’t see anything special that you’d need a more expensive version of Windows for. This should be using your processor’s virtualization capabilities, right?

Yeah, but it uses their Hyper-V hypervisor, which is limited to the Pro and Enterprise versions for no reason other than money.

Re: Windows Sandbox

#93
post #88

Earlier quoted context omitted.

I really doubt that, but I can't easily argue with an anecdote, so sure. It happened, probably 15 years ago. Windows was famous for tons of installers bundling toolbars, but that's never been an epidemic on Mac. These days, Macs will not install unsigned software by default, and you can lock that down to App Store only with a single setting change, so they're certainly not getting bundled malicious toolbars from inst…

But I don't think "it just happens" on windows either (outside of OEM crapware, which granted is pure dirt). Most of the time it is unsophisticated users led to click and install things themselves. An application signature won't help.

how would application signing not help?

if the OS won't let the user install the malware, that's the end of the line.

As I said in my original comment, I don't think Windows 10 is as fragile as earlier versions. A large part of this is the additional enforcement around application signing, even though it isn't as strong as what macOS does by default.

In earlier versions of Windows, it absolutely did "just happen" from a non-technical user's point of view. Linux, macOS, and (to a slightly lesser extent) Windows 10 do not allow it to "just happen".

Re: Windows Sandbox

#94
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

More abstractly: A company adds a new feature to help sell a product.

Re: Windows Sandbox

#95
post #77

Can the app detect if it's in the sandbox? If so, then it could just behave differently in the sandbox and then when used outside behave another way. I think the Linux systemd folks have the right idea with just running processes in their own cgroup regardless, this thing where programs go mucking around with stuff all over the place should be relegated to the past at this point.

It is stated that "every time Windows Sandbox runs, it’s as clean as a brand-new installation of Windows", so it seems that such an app could simply look for the presence of any non-bundled software or any non-default settings to get a rough idea.

Re: Windows Sandbox

#96
post #92

Earlier quoted context omitted.

Isn’t this basically a virtual machine, though? I don’t see anything special that you’d need a more expensive version of Windows for. This should be using your processor’s virtualization capabilities, right?

Yeah, but it uses their Hyper-V hypervisor, which is limited to the Pro and Enterprise versions for no reason other than money.

What other reason would there be to put an advanced feature in a more expensive version of something?

Re: Windows Sandbox

#97
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

I paid 13€ for an Microsoft Windows 10 Pro OEM key. I thought everyone is doing this as well?

I paid 0 EUR for Linux. My school works with Windows stuff and Microsoft doesn't even provide us with free keys. It's ridiculous. Let's just keep all school stuff open source.

Re: Windows Sandbox

#98
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

The same goes for full disk encryption, it isn’t included in the cheapest edition I installed on an old laptop for my mother. Now booting with veracrypt takes 2 minutes. Needless to say I had to get her a chromebook: new laptop, easy to use, secure and for the price of one windows license. This is what will get Microsoft in the end.

Re: Windows Sandbox

#99
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

While your statement is reasonable, it's interesting seeing a Mac user complain about things being too expensive. Is it fundamentally worse to overcharge for software over the hardware?

Re: Windows Sandbox

#100

Earlier quoted context omitted.

depending on the pirated game this might be a good thing :-P

in what game is a performance hit desirable?

Some games physics engines break down once you go past a high enough framerate, such as the fallout games a performance hit would likely keep you below the 125 fps where it begins to break
Post reply on HN