Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sandbox, user specifies access to certain files (like you can do limiting access to certain gallery items on android).

Then changes made to files should be stored as deltas to the original.

But realistically a good readonly/write new backup solution is needed, you never know when something bad might happen.



Okay so you give the sandboxed app access to ~/Documents and those get encrypted…

I think most people don’t care about their system directories but their data?

Backups and onedrive for enterprises, yes. :)


Obviously if you give all sandboxed processes access to /, that doesn't improve anything.

The idea is that you'd notice that your new git binary is trying to get access to /var/postgres, and you'd deny it, because it has no reason to want that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: