Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
History
Fiction
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts115/v4/b0/64/80/b0648074-941b-5370-1b0e-6d0475806689/mza_13084197499987448562.jpg/600x600bb.jpg
Security Headlines
Firo Solutions
25 episodes
4 days ago
Security Headlines is a podcast about the latest security vulnerabilities with in the cyber security field. So if your interested about the latest security holes no mather if you are a tech savy penetration tester, a devops person, a programmer or just generally interested in the latest technology security news. Security headlines is here for you Security headlines is perfect to listen on when you want a quick update, on the way to work or when you are taking a walk out side The podcast is produced by firosolutions.com
Show more...
Tech News
News
RSS
All content for Security Headlines is the property of Firo Solutions and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Security Headlines is a podcast about the latest security vulnerabilities with in the cyber security field. So if your interested about the latest security holes no mather if you are a tech savy penetration tester, a devops person, a programmer or just generally interested in the latest technology security news. Security headlines is here for you Security headlines is perfect to listen on when you want a quick update, on the way to work or when you are taking a walk out side The podcast is produced by firosolutions.com
Show more...
Tech News
News
https://d3t3ozftmdmh3i.cloudfront.net/production/podcast_uploaded_episode/3758595/3758595-1598869184872-769c852fe9755.jpg
Security Headlines bubblewrap podcast special
Security Headlines
43 minutes 2 seconds
5 years ago
Security Headlines bubblewrap podcast special

In modern stacks, a large chunk of applications run in container environments   

such as docker and systemd-nspawn.  However, these applications are not built for security.   

The security community has proven it again and again that privilege escalation attacks   

are very serious with attacks such as Dirty Cow and CVE-2016-3135.   


A way to tackle the problems of running applications with a low privilege user without   

that application being able to interact with other running applications is to use *user namespaces*.      

Using user namespaces you can hide process id's to the applications and provide a more sandboxed environment.   

  

Alex wanted to the distribution of multiplatform applications easy 

which led him to sandboxing and namespaces, today he   

maintains the "chroot on steroids" project *bubblewrap* which is a sandbox platform for running    

sandboxed applications in different namespaces.    


Alex is also a long time user of Linux, with 20 years working for Redhat.   

He started to code on the commodore 64 and has been a developer ever since. In school he  

got introduced to Solaris and jumped deeper and deeper into Linux rabbit hole.   


Working on Linux allows Alex to work from home in the suburbs of Stockholm  

and work on programs that get used by a global user base.


In this episode, we talk about how it has been to work on sandboxed   

desktop applications and how flatpak has grown.    


So far there a has been a handful of different CVE's for bubblewrap 

that we talk about.


Flatpak has gotten bigger and bigger and "flathub" has come to see the light

, flathub is a place where all Linux users can get sandboxed desktop

applications.


Flathub is running on a stable Rust backend, Alex picked Rust to be the backend as one of his first larger Rust projects.  

We of course talk about how Rust is becoming more part of our daily lives  

as more and more applications are being ported to it, like librsvg journey from being written in C to now being a rust code base, as well as libraries  

being written in Rust.  


If you are maintaining an application with a graphical user interface and you target 

an audience that is running Linux on the desktop, we recommend   

that you get your application on flathub.   

Here is a guide on how you can do that:   

https://github.com/flathub/flathub/wiki/App-Submission


This podcast was made possible with running zoom with flatpak:   

$ flatpak remote-add --if-not-exists flathub https://dl.flathub.org/repo/flathub.flatpakrepo   

$ flatpak install flathub us.zoom.Zoom 

$ flatpak run us.zoom.Zoom


External links:  

https://github.com/containers/bubblewrap  

https://flathub.org/home 

https://en.wikipedia.org/wiki/Slirp  

https://github.com/rootless-containers/slirp4netns   

https://podman.io/    

https://github.com/GNOME/librsvg   

https://blogs.gnome.org/alexl/ 

https://twitter.com/gnomealex

https://lkml.org/lkml/2016/3/9/555

https://lwn.net/Articles/657744/  

https://blog.firosolutions.com/   

   


Security Headlines
Security Headlines is a podcast about the latest security vulnerabilities with in the cyber security field. So if your interested about the latest security holes no mather if you are a tech savy penetration tester, a devops person, a programmer or just generally interested in the latest technology security news. Security headlines is here for you Security headlines is perfect to listen on when you want a quick update, on the way to work or when you are taking a walk out side The podcast is produced by firosolutions.com