Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

261–270 of 328 posts

Re: Windows Sandbox

#261

Earlier quoted context omitted.

As a kid, my favorite game was Norton CleanSweep. I couldn't stop watching it restore state, it was a bliss. ps: coincidentally, I was just starting to use linux firejail on a daily basis.. very very useful.

Yes firejail is awesome, but you can only block writes to directories. What I'm looking for is an option to redirect all writes to single directory. This should be transparent (app still might think is writing willy nilly, but in reality all writes would be redirected let's say to ~/app).

I'm pretty sure you actually can do this with firejail, see: --overlay and --overlay-named. For some reason it looks like these are hardcoded (yay, UNIX culture!) to point to `$HOME/.firejail/`.

Re: Windows Sandbox

#262

Earlier quoted context omitted.

I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files. I'm not arguing that a decent package manager is a better than none - but they are solving all issues you claim they do. Pretty much all OSs, including windows, have ways to view which…

> I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files. Got any examples of that? You'd expect only docker to write to /var/lib/docker, mysql to write to /var/lib/mysql. etc. Not discounted that I've overlooked something but a quick look…

> Got any examples of that?

Not the person you were talking to, but looking at certbot, it puts files into /lib/systemd/system/ and /etc/cron.d/ with root:root.

Re: Windows Sandbox

#263

Earlier quoted context omitted.

Try explaining how and when(!) to use this to your HR department, then tell me it's not fancy tech. "My spreadsheet won't open" 'don't use sandbox for that' "But you said every file I downloaded" 'no, only exe' "I opened the PDF exe, edited it, now it's gone" 'self-extracting zips from our payroll system are fine'

So right... this is clearly a "PRO" feature. For normal users the by far better solution is still: Do not install any EXE from unknown sources. Or even better: Do not install anything new in the first place.

Not that I disagree with what you're saying per se, since it really is the simplest option, but as technologists we really need to get over this idea that people shouldn't be allowed to actually use a computer to do computer stuff. Mobile OSs got it pretty close to right: self-contained applications that are sandboxed by default. We need to embrace that concept in personal desktop computers, only without the stupid store (and that includes a package manager) and with complete disk portability of the applications. Basically, the way desktop computer OSs worked in the 90s, only with sandboxing by default.

Re: Windows Sandbox

#264

Earlier quoted context omitted.

> Surely not avoiding AV completely. Exactly that.

Ok, what about for the 99% of the population that that won't work for?

Use ChromeOS, Android, or iOS.

Seriously, AV is pointless software. It will false-positive often, it will false-negative slightly less often, and it will introduce a performance degradation 100% of the time regardless. It is a bad solution to the problem of malware.

Re: Windows Sandbox

#265
post #262

Earlier quoted context omitted.

> I have plenty of files in /var/lib/ that are not owned by any package, same in /var/log/ , /var/cache/ , /etc/sysconfig/ and other directories - their parent directory is owned by a different package than the ones creating these files. Got any examples of that? You'd expect only docker to write to /var/lib/docker, mysql to write to /var/lib/mysql. etc. Not discounted that I've overlooked something but a quick look…

> Got any examples of that? Not the person you were talking to, but looking at certbot, it puts files into /lib/systemd/system/ and /etc/cron.d/ with root:root.

Thank you. I've not used certbot so excuse the dumb question, but is certbot doing that during install (ie via the package manager) or during program execution (ie when the certbot ELF is launched)?

I shouldn't expect too much in /lib/systemd/system is installed outside of package managers but I agree it does happen and at least they're generally quite easy to identify which service file does what.

crontab is definitely one of those nasty things that can often get forgotten about though (and I speak from unfortunate experience there hah!)

We're really drifting into the domain of Puppet and it's ilk now though.

Re: Windows Sandbox

#266
post #38

Only Microsoft would come up with a new security feature and then intentionally and arbitrarily limit its availability to the most expensive version of their OS. This is the same company that thinks putting ads in the fucking file explorer is appropriate on an OS they charge hundreds and hundreds of dollars for.

The same goes for full disk encryption, it isn’t included in the cheapest edition I installed on an old laptop for my mother. Now booting with veracrypt takes 2 minutes. Needless to say I had to get her a chromebook: new laptop, easy to use, secure and for the price of one windows license. This is what will get Microsoft in the end.

I question your mother's need for full disk encryption.

Re: Windows Sandbox

#267
post #221

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

> they have started to add ads to the login screen and my start menu A coworker has asked what reasons I could have for not wanting to run "the best OS". this is enough for me.

[deleted]

Re: Windows Sandbox

#268

Earlier quoted context omitted.

Yes firejail is awesome, but you can only block writes to directories. What I'm looking for is an option to redirect all writes to single directory. This should be transparent (app still might think is writing willy nilly, but in reality all writes would be redirected let's say to ~/app).

I'm pretty sure you actually can do this with firejail, see: --overlay and --overlay-named. For some reason it looks like these are hardcoded (yay, UNIX culture!) to point to `$HOME/.firejail/ `.

this is exactly what i was looking for. thanks

Re: Windows Sandbox

#269
post #99

Earlier quoted context omitted.

While your statement is reasonable, it's interesting seeing a Mac user complain about things being too expensive. Is it fundamentally worse to overcharge for software over the hardware?

I think the problem is not that windows pro costs money. The problem is that Microsoft also sells a second-class version of their OS that is really shitty. From a pure brand perspective, the smart move for Microsoft would be to stop selling windows home.

And while they are at it rethink the "OS as a service" strategy. I don't get the often cited comment on how Microsoft transformed itself under Nutella. They just take the steps they are forced to make because a lot of developers ran to different platforms.

I think MS-software to be less attractive than any time before. Be that windows, their office suite or their cloud landscape, which mainly excels at being slow. And stronger competitors are not the reason for decisions that are mostly not consumer oriented.

Re: Windows Sandbox

#270

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

The thing that bothers me the most about the differentiation between home and pro is that they both include the same set of defaults. Even in Windows Server, Windows Explorer includes links to Videos and Music as default. Why....

Compatibility and familiarity most likely. Server cuts pretty much everything that wouldn't be used by a role such as remote desktop host, what you see left is what is actually used in real world cases. In the particular case of links to Videos/Music the remote desktop host role would need to support them. I mean yeah they could dynamically add the links based on use case discovery of which roles that need them... or they could just include the default explorer profile and nobody really cares that the links are there as they are on every other Windows install.

Now when it comes to things meatier than a few shortcuts they are much more willing to go modular. See nano server.

Post reply on HN