SUDO with sandbox -X integration

Fedora team have developed sandbox -X, a tool allowing to run programs from desktop in sandbox, but still connected to X server. We should integrate this with Sandbox -X to avoid security holes by running some application as another user by sudo.

People are often using graphical tools as root on unprivileged user. PolicyKit is still not satisfied.


sudo /sbin/yast2


icons/user_comment.png J. E. wrote: (8 years ago)

What exactly are you trying to protect against when su-ing to root anyway?

icons/user_comment.png S. L. wrote: (8 years ago)

Sudo doesn't remember X Cookie in default configuration. That was changed in OpenSUSE, but it's insecure. Using Sandbox -X we ensure no connection with current X session is possible and we can working with graphical tool.

I don't believe this is necessary, while running application as root. Some times root or other user will change effective userid to example peter UID.

