Re: [NZOSS-Openchat] Qubes-OS
Thomi Richards <[email protected]>
| Newsgroups | gmane.org.user-groups.linux.dunedin.general |
|---|---|
| Message-ID | <CAN2KdQ8ci=2LSrZv1pU9m9bx64Ew4F6RePgNJyFhdOG1-P2ViQ@mail.gmail.com> |
Hi, On 7 February 2014 11:09, Jim Cheetham <[email protected]> wrote: > On Wed, Jan 22, 2014 at 9:28 AM, Thomi Richards <[email protected]> wrote: > > Speaking of AppArmour, one of the cool things we're doing on Ubuntu Touch > > (the phone OS) is making every application run inside an AppArmour > > container. I *think* similar work is happening on the desktop side, but > TBH > > I'm not on the right mailing lists to give you any more accurate > > information. It seems like a pretty fundamental shift towards a much > better > > application security model than anything I've seen previously on Linux > (any > > distribution). > > This seems to be the way that both Android and iOS work, and is also > the primary reason why there are no effective anti-virus products on > those platforms - there is no way that the AV apps can get permission > to halt/erase/uninstall malware apps. Best they can do is to suggest > to the end-user that they manually uninstall the malware ... > Yeah, I realise I wasn't very clear earlier... > > Hopefully Ubuntu Touch will be able to grant enhanced permissions to > some applications somehow ... :-) > I didn't mean to suggest that Andoid apps are uncontained, that's obviously wrong, but I can see how it reads like that. The problem with andoid apps is that users are asked to accept which permissions to grant an app at install time, with no information regarding *why* the app wants those permissions. If I install a fitness tracking andoid app, and it asks for network access, GPS access, contact list access, I can think of perfectly legitimate reasons for the app needing those permissions. Once it's installed, it may well be sending my location and contact list to the russian mafia... I've granted it permissions to those resources permanently, and there's no (easy) way of knowing what it's actually doing. We're going in a different direction. You're best off reading it from the horses mouth: http://mdeslaur.blogspot.co.nz/2013/12/ubuntu-touch-and-user-privacy.html but the short version is that the user gets to decide which information to share with an app at run time, and gets given context around what the information is for. Cheers, -- Thomi Richards _______________________________________________ DunLUG mailing list [email protected] http://lists.ethernal.org/listinfo/dunlug DunLUG Wiki - http://dunlug.kallisti.net.nz/