[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-talk] Flatpak, Re: Tor Browser Bundle as a "Snap" package
Nathaniel Suchy <me@xxxxxxxxxxx> writes:
> The confinement capabilities of "Snap" packages are quite interesting. As
> Tor Browser continues to grow in usage, I'm interested in seeing what new
> techniques are adopted to improve security. What do you all think about the
> usage of a container (Snap or otherwise) to improve security?
Check latest news on CentOS and Ubuntu removing Bubblewrap (a sandboxing
tech used by Flatpak) support.
Warning: Unlike when using a separate user and a separate log-in
session, bubblewrap not only exposes security vulnerabilities in the
kernel but also in the window compositor. Users should be aware that
running untrustworthy code in bubblewrap is still not safe.
tor-talk mailing list - tor-talk@xxxxxxxxxxxxxxxxxxxx
To unsubscribe or change other settings go to