firejail-profiles icon indicating copy to clipboard operation
firejail-profiles copied to clipboard

cool profiles

Open nyancat18 opened this issue 7 years ago • 7 comments

  • [ ] openvpn
  • [x] ~eddie (for airvpn...A VERY COOL vpn but premium)~,
  • [ ] i2p (taking as base the i2prouter with systemd services installed at /opt)
  • [ ] freenet
  • [x] dia (ms visio like)
  • [x] geany (a COOL IDE)

nyancat18 avatar Apr 12 '17 00:04 nyancat18

Added Dia! 😄

chiraag-nataraj avatar Jun 02 '17 23:06 chiraag-nataraj

With respect to geany, won't the profile depend on which plugins you need? Like, if you're never going to use the C stuff, then giving geany access to gcc is a terrible idea.

chiraag-nataraj avatar Jun 03 '17 00:06 chiraag-nataraj

@nyancat18 What level of security would you like for geany? That is, what exactly do you use it for? Because that will definitely determine how restricted the profile is. I can also completely leave off private-bin, but that's not exactly that secure...

chiraag-nataraj avatar Jul 14 '18 19:07 chiraag-nataraj

I would recommend that you use systemd to sandbox system services like openvpn (and related VPN services), i2p, and freenet. You get the same granularity as with firejail (sometimes more), and with system services, you get the full range of options systemd has to offer (unlike with user services, where firejail is really useful).

chiraag-nataraj avatar Jul 21 '18 22:07 chiraag-nataraj

I'll try to bring in a profile for geany though.

chiraag-nataraj avatar Jul 21 '18 22:07 chiraag-nataraj

Done!

chiraag-nataraj avatar Jul 21 '18 22:07 chiraag-nataraj

After reconsidering, I'll try to bring in a profile for openvpn, i2p, and freenet. Since I don't have AirVPN, I can't test eddie at all, but if you want to bring in a profile for that, I'd be happy to merge it. Re-opening as a result.

chiraag-nataraj avatar Jul 28 '18 16:07 chiraag-nataraj