[tor-talk] Flatpak, Re: Tor Browser Bundle as a "Snap" package

Mykola Nikishov mn at mn.com.ua
Thu Feb 21 12:55:53 UTC 2019


Nathaniel Suchy <me at lunorian.is> writes:

> The confinement capabilities of "Snap" packages are quite interesting. As
> Tor Browser continues to grow in usage, I'm interested in seeing what new
> techniques are adopted to improve security. What do you all think about the
> usage of a container (Snap or otherwise) to improve security?

Check latest news on CentOS and Ubuntu removing Bubblewrap (a sandboxing
tech used by Flatpak) support.

    Warning: Unlike when using a separate user and a separate log-in
    session, bubblewrap not only exposes security vulnerabilities in the
    kernel but also in the window compositor. Users should be aware that
    running untrustworthy code in bubblewrap is still not safe.

[0] https://github.com/projectatomic/bubblewrap
[1] https://wiki.archlinux.org/index.php/Bubblewrap
[2] https://blog.torproject.org/q-and-yawning-angel

-- 
Mykola



More information about the tor-talk mailing list