Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

131–140 of 328 posts

Re: Windows Sandbox

#131
post #70

Earlier quoted context omitted.

> Nowadays it's almost impossible to uninstall an app completely, because most of them creating files willy nilly. This has always been the case on Windows. In fact if anything, nowadays it’s better than its ever been because thanks to the UAC and other controls Microsoft have put in place, developers aren’t so free to do whatever they like to the host machine. But that’s remember a time before the UAC when it would…

It really is. I'm not talking about app binaries only. But about all files that app creates after install. Most of the reside in home dir, but stays there forever. Like various cache files, settings, ... And most of the time they are not confined to single dir.

> Most of the reside in home dir, but stays there forever. Like various cache files, settings, ... And most of the time they are not confined to single dir.

I think you need to support that statement. I believe the vast majority of software on common Unix distros creates no files in $HOME[1], and of those that do the majority use one folder in home[2], which *should+ be used for configuration, and often you don't want it automatically uninstalled on software removal.

The few I can think of that quote to multiple locations do so because the extra locations are shared folders. For example, I would not want my downloads directory removed on uninstallation of Firefox.

  1: E.g. Most things in /bin, and /usr/bin.

  2: other than what I outlined above, I can't think of any that use multiple directories. If it's truly a common as you say, you should be able to provide some examples.

Re: Windows Sandbox

#132

I wish they would have added the option to have the data persist. I have a bunch of software that I run only a few times per year, but I don't want to go through the hassle of re-installing it every time I need to run it. It would have been so much more useful if the data could persist.

Wouldn't that make it an ordinary VM?

Re: Windows Sandbox

#133

Earlier quoted context omitted.

It seems to me that no matter what happens two classes of users are going to be created: those that can pay for security and those that cannot. Ultimately Apple's pricing means all their users are first class - hence security as a bread-and-butter feature on their platforms. In MSFT's case they're going to have low and high cost consumers, so they segment those users into the two relevant classes. None of this is goo…

> Ultimately Apple's pricing means all their users are first class - hence security Yeah... Good luck running the latest version of iOS on an older iPhone. (Many are still have a 5/6 and you really don't want to update those if you value a reasonable experience and latency.)

iOS 12 runs on everything through the 5S, and notably improved performance over iOS 10/11 on the same devices. [1] is a bunch of benchmarks from back in the beta period.

My kid has it on a 6, and it's legitimately good performance there.

Good luck getting the latest Android onto a 5 year old handset without jumping through some non-trivial hoops.

[1]: http://www.iphonehacks.com/2018/09/ios-12-performance-improv...

Re: Windows Sandbox

#134
post #70

Earlier quoted context omitted.

> Nowadays it's almost impossible to uninstall an app completely, because most of them creating files willy nilly. This has always been the case on Windows. In fact if anything, nowadays it’s better than its ever been because thanks to the UAC and other controls Microsoft have put in place, developers aren’t so free to do whatever they like to the host machine. But that’s remember a time before the UAC when it would…

You're contradicting yourself in your first and second paragraph... Those proper package managers still rely on the packager doing things correctly - just as it would creating a windows .msi. There's plenty of linux packages that creates files during operation in their designated /var/log/xxx /var/db/xxx /etc/xxx /home/xxx/ directories that you're not able to query using the package manager.

> You're contradicting yourself in your first and second paragraph...

Those two paragraphs are talking about different OSs. 1st paragraph is talking about Windows, 2nd paragraph is talking about non-Windows systems with first-class package managers such as ArchLinux, Debian, CentOS, FreeBSD, etc.

> Those proper package managers still rely on the packager doing things correctly

Sure, but the point is you can query what the package manager has done.

> There's plenty of linux packages that creates files during operation in their designated /var/log/xxx /var/db/xxx /etc/xxx /home/xxx/ directories that you're not able to query using the package manager.

That's half true. You can query that /var/db/xxx and /var/log/xxx has been created by the package manager and often the directories (and their contents) will be owned by the user which the daemon runs under.

However I do agree with the point regarding your $HOME directory and actually made that point myself:

> Of course you still have the problem of the software writing files during its operation but that should be limited to $HOME (on POSIX systems) or any path that is writable by the owner / group of the user that application runs as (which should be limited even if it’s a system service).

As an aside, you can also query what files a particular application has open. In fact there are a few ways to do this from querying the /proc/$PID directory through to tools like `lsof`.

Re: Windows Sandbox

#135
post #130

Earlier quoted context omitted.

It seems to me that no matter what happens two classes of users are going to be created: those that can pay for security and those that cannot. Ultimately Apple's pricing means all their users are first class - hence security as a bread-and-butter feature on their platforms. In MSFT's case they're going to have low and high cost consumers, so they segment those users into the two relevant classes. None of this is goo…

> unfortunately for most laypeople it's security and privacy that's on the chopping block. I think this is why we need legislation: The free market obviously can't sort this out to peoples' benefit. I have a couple Android devices I can't figure out how to update, so I'm afraid to use them for anything serious. If the author isn't responsible for writing crappy code, and I can't fix it, then where's my lemon law?

I agree, but have one nitpick - it's not that the free market can't sort this out, but that this is exactly the solution the free market is set up to organically create. Can't afford the tech? Sell your identity to marketers! That's all free market and I don't think we give the "free market" (scare quotes because we're so far from that in actuality it's painful) enough credit for creating these exact problems.

Re: Windows Sandbox

#136
post #68

Earlier quoted context omitted.

Then make Hyper-v home. Seriously this is a killer feature needed by everybody. And specially the non-pro users.

A lot (most?) of the hardware Home runs on doesn't support hardware virtualization.

£2,500 Dell XPS ships Home out of the box unless specified otherwise.

Windows SKU has nothing to do with hardware.

https://www.dell.com/en-uk/shop/2-in-1-laptops/new-xps-15-2-...

Actually I can't seem to configure that directly from dell to come with Pro lol. Seems there's a question about that too.

Re: Windows Sandbox

#137
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

I paid 13€ for an Microsoft Windows 10 Pro OEM key. I thought everyone is doing this as well?

Power of defaults. People have Home, they stay on it.

Nonetheless, if you can go from Home to Pro with 13€ it feels quite ridiculous that there is a Home/Pro distinction at all from the very start.

Re: Windows Sandbox

#138
post #99
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

While your statement is reasonable, it's interesting seeing a Mac user complain about things being too expensive. Is it fundamentally worse to overcharge for software over the hardware?

I imagine that people who buy a Mac, want to have a Mac and it's their choice to pay. Maybe I am wrong. But people who buy a PC, have no choice but pay the Microsoft tax for the pre-installed Windows on it.

So, yes, it is reasonable to be angry when they put advertisement on the hardware that you paid on the OS that you paid together with the hardware. It is creepy, and belittling too.

Luckily IT professionals have yet the choice to install something else. Let's see how long it takes until we have no choice what software is allowed to run on devices that we buy.

Sorry for the rant.

Re: Windows Sandbox

#139
Ok, we're taking bets on what the first sandbox-escaping attack will target. My money is on a privilege escalation based on this gem:

> Our solution is to construct what we refer to as “dynamic base image”: an operating system image that has clean copies of files that can change, but links to files that cannot change that are in the Windows image that already exists on the host. The majority of the files are links (immutable files) and that's why the small size (~100MB) for a full operating system.

Post reply on HN