top | item 46879678

(no title)

IcyWindows | 27 days ago

Windows has had this for over a decade, but no one wants to put their application in a sandbox.

discuss

order

akdev1l|27 days ago

If a sandbox is optional then it is not really a good sandbox

naturally even flatpak on Linux suffers from this as legacy software simply doesn’t have a concept of permission models and this cannot be bolted on after the fact

okanat|27 days ago

The containers are literally the "bolting on". You need to give the illusion of the software is running under a full OS but you can actually mount the system directories as read-only.