Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

241–250 of 328 posts

Re: Windows Sandbox

#241

Earlier quoted context omitted.

Sandboxie is actually still superior to this Windows Sandbox, as it allows you to continually run an app in the sandbox. In Windows Sandbox, once you close the app, your stored data, settings etc. are gone. But yes, it's UI is horrible and might be difficult to setup (apps with incorrect setup might not even run).

They clearly have different use cases, I don't think it's fair to say one is necessarily better because of it.

Yes you're right, I was bit harsh, but not intentionally.

Re: Windows Sandbox

#242
post #70

Earlier quoted context omitted.

> Nowadays it's almost impossible to uninstall an app completely, because most of them creating files willy nilly. This has always been the case on Windows. In fact if anything, nowadays it’s better than its ever been because thanks to the UAC and other controls Microsoft have put in place, developers aren’t so free to do whatever they like to the host machine. But that’s remember a time before the UAC when it would…

As a kid, my favorite game was Norton CleanSweep. I couldn't stop watching it restore state, it was a bliss. ps: coincidentally, I was just starting to use linux firejail on a daily basis.. very very useful.

Yes firejail is awesome, but you can only block writes to directories. What I'm looking for is an option to redirect all writes to single directory. This should be transparent (app still might think is writing willy nilly, but in reality all writes would be redirected let's say to ~/app).

Re: Windows Sandbox

#243
post #192

Nowadays it's almost impossible to uninstall an app completely, because most of them creating files willy nilly. And it's same on all known OSes. The side effect we see is system size growing in time. IMO running an app in a sandbox should be the default option. On Windows, I used to like sandboxie, which virtualized every write into single directory. Uninstall was easy as removing that dir. This MS sandbox doesn't a…

> Nowadays it's almost impossible to uninstall an app completely, because most of them creating files willy nilly. And it's same on all known OSes. The side effect we see is system size growing in time. Unless I am mistaken, I don't think this is the case for iOS, Android, ChromeOS, FirefoxOS, and many game consoles. This is really just a problem with desktop and server operating systems, not with operating systems a…

Yes, I forgot to mention mobile OSes. Specially iOS, doesn't keep any app files on disk when app is uninstalled. Android apps tend to keep files regularly on SD card (virtual or real one). Some apps might benefit from this (eg. you don't have to redownload huge map files for navigation app), but paradoxically Sygic Navigation app isn't storing map files on sdcard, but some crappy apps, where it doesn't make sense are. So in practice it's not very different from what we have on PC.

Re: Windows Sandbox

#244

Earlier quoted context omitted.

The same goes for full disk encryption, it isn’t included in the cheapest edition I installed on an old laptop for my mother. Now booting with veracrypt takes 2 minutes. Needless to say I had to get her a chromebook: new laptop, easy to use, secure and for the price of one windows license. This is what will get Microsoft in the end.

Secure and inexpensive as long as you don't mind paying with your privacy. I'm worried that this is going to be the compromise we're all forced to make in the future.

This is a legitimate concern for me, but almost no part of my mother's life takes place online. She did have a mac, but lost that and there is no money for a new one. She also has an android phone, so the privacy argument applies here as well and is still very valid. Eventually I will get her on a mac or ubuntu laptop or something like that.

In terms of usability I have to tip my hat to Google. ChromeOS is very easy to use so far. Probably until chromebook vendors start adding all sorts of their own shitty tools and accounts like Huawei has done with their phones.

Re: Windows Sandbox

#245

Earlier quoted context omitted.

You're contradicting yourself in your first and second paragraph... Those proper package managers still rely on the packager doing things correctly - just as it would creating a windows .msi. There's plenty of linux packages that creates files during operation in their designated /var/log/xxx /var/db/xxx /etc/xxx /home/xxx/ directories that you're not able to query using the package manager.

> You're contradicting yourself in your first and second paragraph... Those two paragraphs are talking about different OSs. 1st paragraph is talking about Windows, 2nd paragraph is talking about non-Windows systems with first-class package managers such as ArchLinux, Debian, CentOS, FreeBSD, etc. > Those proper package managers still rely on the packager doing things correctly Sure, but the point is you can query wha…

I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files.

I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do.

Pretty much all OSs, including windows, have ways to view which processes has a file open

Re: Windows Sandbox

#246

Quick thoughts... First thought: I'd love to be able to ship an app w/ this enabled by default (i.e. it's an ephemeral app w/ no local data storage). Second thought: I'd love to pause this snapshot and resume it. Too many apps store preferences that you don't want to reconfigure just because you want isolation from the rest of the system each execution. Third thought: Instead of always-dispose-on-app-close, I would l…

Regarding your first thought, you can get pretty close today with Windows Isolated App Containers. Chromium uses this under the hood.

Re: Windows Sandbox

#247
post #2

Please do not make this a Pro / Enterprise feature. I do remote tech support for my parents and would love for them to browse / use apps in a sandbox.

I took an inventory of which apps my parents use: email, solitaire, Youtube, and some web browsing. That was it. Linux is good at doing those things, so I put them on Xubuntu (my preferred distro) about 8 years ago. Once my mom understood that the UI was similar enough to Windows, she didn't mind. Its been remarkably stable (and usable) ever since.

Re: Windows Sandbox

#248
post #14

How detectable will it be? I doubt this will make the lives of malware analysts any easier.

As much as hyper-v. Without sounding disparaging (because this is really cool), its just a one-click application-on-windows-on-hyper-v. So all the pros and cons come with it.

Yeah, I assumed that "sandbox" implied some smarter isolation technique closer to eg Linux namespaces instead of just app-v in a new shiny packaging. Nothing new for the malware-analysis use-case.

Re: Windows Sandbox

#249

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

If you dig around in settings you can disable those ads (aka "suggestions"). I've not found a way to stop Defender from advertising Microsoft accounts or OneDrive via the security warning system. But they can at least be dismissed until the next feature update puts them back.

> But they can at least be dismissed until the next feature update puts them back.

This is damning praise. If intentional it means users are't being offered permanent control of the software, only momentary changes. I dare say they aren't even 'options' at that point since the word implies lasting choice; at least for me.

Re: Windows Sandbox

#250
post #177

Earlier quoted context omitted.

I am not misunderstanding you. Your entire comment was centered around a perceived unfairness regarding price: > most expensive version of their OS. > they charge hundreds and hundreds of dollars for. To be clear here, I'm not defending Windows. I agree with you that what they do is not constructive for their users. I'm merely pointing out it's ironic for Mac users sit on their throne and decry Windows' practices whi…

Are you seriously trying to claim that Macs are overpriced by hundreds of dollars by trying to compare them against an ATX desktop? Or do you have some more reasonable comparison in mind of Apple and non-Apple products that actually compete in the same market segment, and where the Dell/Lenovo/HP/whatever is significantly more upgradable? And do you have any reasonable complaints about the security and privacy of a m…

Not a parent commenter, but I have some examples of upgradeability/repairability. Dell XPS line of laptops has upgradeable storage and screwed-in batteries. 15" variant has upgradeable RAM and wireless card. The keyboard is attached with screws instead of being permanently fixed to chassis and costs significantly less to order and replace yourself should you find a need for it. Similarly in the worst case scenario, there are replacement motherboards on eBay for $550 or sometimes less which you could again order and replace yourself (or upgrade your base CPU option with).

And both 13" and 15" Dells have a fingerprint sensor which is as snappy as Touch ID without being bundled with a thin strip of touchscreen and a $200 price hike.

That's because these laptops are designed to be serviced on-site by repairmen who are not always so bright. So I imagine, similar HP offerings are as robust.

Dell's and HP's phone support and warranty support are super awful, though, so this may be a factor for you. For me, the difference between a drink spill costing $600 (and I do it myself) on a $2500 Dell versus $1500 (and I have to lose my files/get a new system) on a $1600 MBP (both true stories) is significant and I'm not rich enough to go for latter.

Post reply on HN