Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

251–260 of 328 posts

Re: Windows Sandbox

#251

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

> I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. Hyper-V does function under the garb of 'Windows Hypervisor Platform' and 'Virtual Machine Platform' even under Windows 10 Home. I have it installed and it provides the…

> So there is no reason why MS cannot implement Windows Sandbox even on Home since the underlying tech actually functions on all Windows editions

By that logic Microsoft could also allow Windows 10 Home to run Active Directory. The reason there's a Pro/Home split is a commercial decision not a technical one, so trying to view it through a technical lens is faulty.

Regardless, if we want to talk about security features Windows 10 Home "should" have, let's talk AppLocker one of the most powerful security tools available. My computer illiterate relatives aren't going to be dropping into Sandbox to test potentially dangerous executable, but AppLocker could be set and forget, blocking execution of dangerous items.

The only thing Microsoft offers on Home is the highly self-serving "Allow apps from the store only." Which adds as many problems as it solves.

Re: Windows Sandbox

#252

Earlier quoted context omitted.

> I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. Hyper-V does function under the garb of 'Windows Hypervisor Platform' and 'Virtual Machine Platform' even under Windows 10 Home. I have it installed and it provides the…

> So there is no reason why MS cannot implement Windows Sandbox even on Home since the underlying tech actually functions on all Windows editions By that logic Microsoft could also allow Windows 10 Home to run Active Directory. The reason there's a Pro/Home split is a commercial decision not a technical one, so trying to view it through a technical lens is faulty. Regardless, if we want to talk about security feature…

But your computer illeterate relatives wouldn't know how to set applocker in the first place, so it does fall within the realm of managed machines which is kind of what pro is for.

Re: Windows Sandbox

#253
post #12

Earlier quoted context omitted.

why not just buy them a pro edition? I know it's more expensive, but that would also get you remote desktop, bitlocker, and group policy, which would all also be great for remote supporting your parents.

I would spend a few hundred extra dollars and just get a MacBook air or mini and install 1blocker on it.

Because you're still left with the same issue? MacOS's security technology is significantly behind Windows, only its relative obscurity protects it.

Re: Windows Sandbox

#254

Earlier quoted context omitted.

> You're contradicting yourself in your first and second paragraph... Those two paragraphs are talking about different OSs. 1st paragraph is talking about Windows, 2nd paragraph is talking about non-Windows systems with first-class package managers such as ArchLinux, Debian, CentOS, FreeBSD, etc. > Those proper package managers still rely on the packager doing things correctly Sure, but the point is you can query wha…

I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files. I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do. Pretty much all OSs, including windows, have ways to view which…

> I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files.

Got any examples of that? You'd expect only docker to write to /var/lib/docker, mysql to write to /var/lib/mysql. etc. Not discounted that I've overlooked something but a quick look in my /var/lib and it's easy to see what is managed by what. So I'm curious what instances you have of a package manager creating a directory and then a completely unrelated daemon writing to that directory.

> I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do.

I'm not claiming they solve all the problems - in fact I literally identified a few problems they don't solve! Plus even those points I identified aside, there will always be edge cases for thing that package manager should have solved but failed to do so.

Perhaps we should turn this discussion on it's head and discuss better ways to solve the problems people are describing? What would your solution be? Or are you ostensibly agreeing with my points but being contrary just for the sake of playing devils advocate?

> Pretty much all OSs, including windows, have ways to view which processes has a file open

Isn't that literally what I just said? (plus I gave a few examples too).

Re: Windows Sandbox

#256

Earlier quoted context omitted.

This. I cannot use docker on my gaming rig to use it as dev machine sometimes because I need VirtualBox on it.

Isn't it just a case of changing a registry value and rebooting?

If switching from games to dev work requires manually patching the system registry and rebooting, then something is horribly wrong.

Re: Windows Sandbox

#257

Earlier quoted context omitted.

> The really tricky problem is when a package must modify an existing shared resource. Such as appending lines to an existing config for example. Pacman creates a .pacnew file and lets you merge it yourself for this very reason.

Seems like that is offloading the tricky bit to the user rather than solving the tricky problem to be honest.

Yeah, but it's very transparent to the user, which is kind of the Arch Way, and to be fair, there are tools to help you, like pacdiff.

Re: Windows Sandbox

#258
post #252

Earlier quoted context omitted.

> So there is no reason why MS cannot implement Windows Sandbox even on Home since the underlying tech actually functions on all Windows editions By that logic Microsoft could also allow Windows 10 Home to run Active Directory. The reason there's a Pro/Home split is a commercial decision not a technical one, so trying to view it through a technical lens is faulty. Regardless, if we want to talk about security feature…

But your computer illeterate relatives wouldn't know how to set applocker in the first place, so it does fall within the realm of managed machines which is kind of what pro is for.

AppLocker isn't available on Pro either.

Re: Windows Sandbox

#259

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

The thing that bothers me the most about the differentiation between home and pro is that they both include the same set of defaults.

Even in Windows Server, Windows Explorer includes links to Videos and Music as default. Why....

Re: Windows Sandbox

#260
post #116

Earlier quoted context omitted.

Where did you buy such a cheap copy of Windows 10 Pro?

Those are digital (unused) licenses, that although can't technically be resold, they "can" be in Europe as they contradict a ruling made in 2012 (I don't have time to dig the link up, unfortunately).

Those cheap licenses are always used. They exploit the fact that these can be used to activate ~10 copies of Windows. It's even worse than that though. One seller could keep track of this limit, but what happens is that a bunch of sellers source their keys from other similar sellers. So they don't even know how many times a key has been used.

Last time I bought one of these 15€ keys for a friend, I had to write to the customer support over 10 times and shuffle through at least 6 different keys until one actually worked.

Post reply on HN