Skip to content

MVP of AppArmor profile that only deny access specific folder #33

@fititnt

Description

@fititnt

Related


Let's do an minimum viable product (MVP) of AppArmor profile that shows how to at block access to specific folder even if running under user who runs the application do have access to the folders.

The #32 is interesting for apps (and not only binaries) that should not have access to internet. But what about software like Zoom, Skype, Spotify, Slack, etc that should have access to internet but could still access private files? Looking deeper on AppArmor, most softwares that ship with Ubuntu, even the ones that already are not isolated with Snaps, do have AppArmor profiles. But this is likely to not apply to other apps.

Metadata

Metadata

Assignees

No one assigned

    Labels

    apparmor-profile"AppArmor is an effective and easy-to-use Linux application security system." https://apparmor.net/beyond-tails

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions