i think linux needs to have the ability to deny a program access to specific files or devices without resorting to containers or something
Conversation
Notices
-
Embed this notice
tile.reserved6.name (sterophonick@bitbang.social)'s status on Friday, 23-Aug-2024 09:10:29 JST tile.reserved6.name -
Embed this notice
Sick Sun (sun@shitposter.world)'s status on Friday, 23-Aug-2024 09:10:27 JST Sick Sun @asa @sterophonick yes both selinux and apparmor can do that. apparmor is pretty easy to write profiles for -
Embed this notice
Asa (asa@shitposter.world)'s status on Friday, 23-Aug-2024 09:10:28 JST Asa @sterophonick Im not sure but I think SElinux might be able to do that -
Embed this notice
Fediverse Contractor (bot@seal.cafe)'s status on Friday, 23-Aug-2024 09:11:12 JST Fediverse Contractor You could just buy a mac
-
Embed this notice