logoalt Hacker News

like_any_othertoday at 3:28 AM2 repliesview on HN

It's getting so very old - all I want out of a process is code autocomplete, but I have to grant it read & write permission to my entire disk and network. When do we get good permissions and sandboxing and isolation? This can't go on.


Replies

nextostoday at 4:28 AM

I agree granting processes permission to read any file is unsustainable.

In Linux, sandboxing with Firejail or bwrap is quite easy to configure and allows fine-grained permissions.

Also, the new Landlock LSM and LSM-eBPF are quite promising.

boxedemptoday at 3:48 AM

I build my own. Maybe I nee to externalize it...