Re: [NZOSS-Openchat] Qubes-OS

Thomi Richards <[email protected]>
Newsgroups gmane.org.user-groups.linux.dunedin.general
Message-ID <CAN2KdQ8ci=2LSrZv1pU9m9bx64Ew4F6RePgNJyFhdOG1-P2ViQ@mail.gmail.com>
Hi,


On 7 February 2014 11:09, Jim Cheetham <[email protected]> wrote:

> On Wed, Jan 22, 2014 at 9:28 AM, Thomi Richards <[email protected]> wrote:
> > Speaking of AppArmour, one of the cool things we're doing on Ubuntu Touch
> > (the phone OS) is making every application run inside an AppArmour
> > container. I *think* similar work is happening on the desktop side, but
> TBH
> > I'm not on the right mailing lists to give you any more accurate
> > information. It seems like a pretty fundamental shift towards a much
> better
> > application security model than anything I've seen previously on Linux
> (any
> > distribution).
>
> This seems to be the way that both Android and iOS work, and is also
> the primary reason why there are no effective anti-virus products on
> those platforms - there is no way that the AV apps can get permission
> to halt/erase/uninstall malware apps. Best they can do is to suggest
> to the end-user that they manually uninstall the malware ...
>

Yeah, I realise I wasn't very clear earlier...


>
> Hopefully Ubuntu Touch will be able to grant enhanced permissions to
> some applications somehow ... :-)
>


I didn't mean to suggest that Andoid apps are uncontained, that's obviously
wrong, but I can see how it reads like that.

The problem with andoid apps is that users are asked to accept which
permissions to grant an app  at install time, with no information regarding
*why* the app wants those permissions.

If I install a fitness tracking andoid app, and it asks for network access,
GPS access, contact list access, I can think of perfectly legitimate
reasons for the app needing those permissions. Once it's installed, it may
well be sending my location and contact list to the russian mafia... I've
granted it permissions to those resources permanently, and there's no
(easy) way of knowing what it's actually doing.

We're going in a different direction. You're best off reading it from the
horses mouth:

http://mdeslaur.blogspot.co.nz/2013/12/ubuntu-touch-and-user-privacy.html

but the short version is that the user gets to decide which information to
share with an app at run time, and gets given context around what the
information is for.


Cheers,

-- 
Thomi Richards

_______________________________________________
DunLUG mailing list
[email protected]
http://lists.ethernal.org/listinfo/dunlug
DunLUG Wiki - http://dunlug.kallisti.net.nz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.