<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="http://dev1galaxy.org/extern.php?action=feed&amp;tid=4999&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Firejail security concerns]]></title>
		<link>http://dev1galaxy.org/viewtopic.php?id=4999</link>
		<description><![CDATA[The most recent posts in Firejail security concerns.]]></description>
		<lastBuildDate>Sat, 28 May 2022 17:38:34 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Firejail security concerns]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=36069#p36069</link>
			<description><![CDATA[<p>firejail from my experience has been pretty good. Issue is when you start running untrusted programs and required to hash out seccomp for hardware and/or syscall access. Along with other security settings that otherwise would make it pretty solid choice.</p>]]></description>
			<author><![CDATA[dummy@example.com (czeekaj)]]></author>
			<pubDate>Sat, 28 May 2022 17:38:34 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=36069#p36069</guid>
		</item>
		<item>
			<title><![CDATA[Re: Firejail security concerns]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35745#p35745</link>
			<description><![CDATA[<div class="quotebox"><cite>dvnUsr wrote:</cite><blockquote><div><p>if it is likely to vanish from Debian/Devuan for similar reasons?</p></div></blockquote></div><p>I wouldn&#039;t think so. Alpine place considerably more emphasis on security than Debian — they don&#039;t even apply the unprivileged user namespaces sysctl patch to their kernel, <a href="https://salsa.debian.org/kernel-team/linux/-/blob/master/debian/patches/debian/add-sysctl-to-disallow-unprivileged-CLONE_NEWUSER-by-default.patch" rel="nofollow">unlike Debian</a>.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Mon, 25 Apr 2022 13:30:47 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35745#p35745</guid>
		</item>
		<item>
			<title><![CDATA[Re: Firejail security concerns]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35706#p35706</link>
			<description><![CDATA[<p>You might possibly enjoy <a href="https://git.devuan.org/devuan/overlay-boot" rel="nofollow">overlay-boot</a> in Devuan&#039;s <span class="bbc">experimental</span> repository.<br />It&#039;s a couple of scripts using <span class="bbc">unshare</span> for namespace separation.</p><p>Add the following line to your <span class="bbc">sources.list</span> for installing it</p><div class="codebox"><pre><code>deb http://pkgmaster.devuan.org/devuan experimental main</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Thu, 21 Apr 2022 02:30:58 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35706#p35706</guid>
		</item>
		<item>
			<title><![CDATA[Firejail security concerns]]></title>
			<link>http://dev1galaxy.org/viewtopic.php?pid=35705#p35705</link>
			<description><![CDATA[<p>11 months ago, the Alpine Linux team withdrew firejail from their repositories, citing security concerns with it:</p><div class="quotebox"><blockquote><div><p><a href="https://gitlab.alpinelinux.org/alpine/aports/-/issues/12643" rel="nofollow">https://gitlab.alpinelinux.org/alpine/a … sues/12643</a></p></div></blockquote></div><p>This looks like it was a sudden thing, and is a little annoying because the suggested Bubblejail replacement is not working properly for me (Alpine v3.15.4; not edge).</p><p>Does anyone know if it is likely to vanish from Debian/Devuan for similar reasons?&#160; If so, is there/will there be a good, KISS, easy-to-use alternative?</p>]]></description>
			<author><![CDATA[dummy@example.com (dvnUsr)]]></author>
			<pubDate>Thu, 21 Apr 2022 01:14:16 +0000</pubDate>
			<guid>http://dev1galaxy.org/viewtopic.php?pid=35705#p35705</guid>
		</item>
	</channel>
</rss>
