Live data from Hacker News

Windows Sandbox

techcommunity.microsoft.com

281–290 of 328 posts

Re: Windows Sandbox

#281

Earlier quoted context omitted.

I would spend a few hundred extra dollars and just get a MacBook air or mini and install 1blocker on it.

Because you're still left with the same issue? MacOS's security technology is significantly behind Windows, only its relative obscurity protects it.

System Integrity Protection would protect against many of the same threats that Windows Sandbox would (since it prevents applications from doing extreme damage to the system even with root), and by default it only lets you install software from developers registered with Apple (either inside or outside the Mac App Store). It'd be more secure out of the box than a Windows system, as if you have admin and are willing to click "yes", you can let an application do anything on Windows (although most attacks can be prevented with the new features in Pro/Enterprise).

Re: Windows Sandbox

#282
> 11. Confirm that the host does not have any of the modifications that you made in Windows Sandbox.

This item on their "Quick Start Guide" doesn't fill me with confidence.

Any takers on how long before an escape is disclosed? I think within 30-60 days.

Re: Windows Sandbox

#283

Seems like a really nice feature. I've been thinking about something like this for a while. I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. The thing that annoys me more (hi MS guys, feel free to tell the relevant peopl…

> I see some people are really annoyed that it isn't available for the Home version and I too am somewhat annoyed but in this case it is somewhat understandable since it depends on a feature that is (somewhat more reasonable) limited to Pro versions. Hyper-V does function under the garb of 'Windows Hypervisor Platform' and 'Virtual Machine Platform' even under Windows 10 Home. I have it installed and it provides the…

Looks like you're singing the proprietary software blues. No worries, just spend more money. That solves everything on Windows.

Re: Windows Sandbox

#284

This is pretty cool, I know where I'm going to run my browser from now on :-).

In case that wasn’t sarcasm: you probably don’t want to run your browser in this, since it already has a sandbox and you’ll have a measurable performance penalty by running in a virtual machine.

"In case that wasn’t sarcasm: you probably don’t want to run your browser in this, since it already has a sandbox and you’ll have a measurable performance penalty by running in a virtual machine."

Actually, what I do want to do more than anything in this sphere is run browsers in a VM. The account containers in firefox is not enough.

This would work without performance penalty if you could chroot jail a gui application. There's almost no overhead in a jail - it's not a full blown VM, just a different chroot.

Here is the best recipe so far:

https://news.ycombinator.com/item?id=14243672

... but of course that's not a fit for OSX, which has no Xserver and blah blah quartz blah blah major spaghetti to get that working. Also OSX does not have 'jail'.

Re: Windows Sandbox

#285

Earlier quoted context omitted.

I think the problem is not that windows pro costs money. The problem is that Microsoft also sells a second-class version of their OS that is really shitty. From a pure brand perspective, the smart move for Microsoft would be to stop selling windows home.

And while they are at it rethink the "OS as a service" strategy. I don't get the often cited comment on how Microsoft transformed itself under Nutella. They just take the steps they are forced to make because a lot of developers ran to different platforms. I think MS-software to be less attractive than any time before. Be that windows, their office suite or their cloud landscape, which mainly excels at being slow. An…

But the subscription model for windows makes a lot of sense, I think. Leaving people on older versions is the same as selling a crippled version of your OS

Re: Windows Sandbox

#286

Earlier quoted context omitted.

Because you're still left with the same issue? MacOS's security technology is significantly behind Windows, only its relative obscurity protects it.

System Integrity Protection would protect against many of the same threats that Windows Sandbox would (since it prevents applications from doing extreme damage to the system even with root), and by default it only lets you install software from developers registered with Apple (either inside or outside the Mac App Store). It'd be more secure out of the box than a Windows system, as if you have admin and are willing t…

Windows 10 has identical defaults (Windows Store install only, with hard locks on certain parts of the system and an integrity checker).

Re: Windows Sandbox

#287
post #2

Please do not make this a Pro / Enterprise feature. I do remote tech support for my parents and would love for them to browse / use apps in a sandbox.

You underestimate your parents likelihood to overgeneralize your sandbox advice. I expect you will be receiving this call months from now:

"You told me to use sandbox to be safe, so I wrote critical document X in a sandbox because I want it to be safe, but now that I rebooted I've lost all of my work."

Re: Windows Sandbox

#288
post #279

Earlier quoted context omitted.

Thank you. I've not used certbot so excuse the dumb question, but is certbot doing that during install (ie via the package manager) or during program execution (ie when the certbot ELF is launched)? I shouldn't expect too much in /lib/systemd/system is installed outside of package managers but I agree it does happen and at least they're generally quite easy to identify which service file does what. crontab is definit…

I'm not sure when those files get created, I just knew about that example off the top of my head because I had to spend some time figuring out why our post-renew hook wasn't working. dpkg -L helps a lot when figuring out where all the files get spread.

> dpkg -L helps a lot when figuring out where all the files get spread.

Well yeah, that was the central point of this conversation :)

Re: Windows Sandbox

#290

Earlier quoted context omitted.

Secure and inexpensive as long as you don't mind paying with your privacy. I'm worried that this is going to be the compromise we're all forced to make in the future.

> Secure and inexpensive as long as you don't mind paying with your privacy. There are obvious alternatives to ChromeOS that are just as secure and just as inexpensive (especially if you have some old hardware just laying around, or else you can just buy refurbished hardware - just about anything made in the last 10 years will do, if not more than that) - and not any less useful than a Chromebook. And they can be upd…

Chrome wins on the mom, grandpa, etc. can easily use it... I've yet to see an OS that is less locked down that's easier to use in practice. Yes, privacy concerns. That said, it's still what I recommend for MOST people not interested in gaming.
Post reply on HN