You are only browsing one thread in the discussion! All comments are available on the post page.

Return

possiblylinux127 ,
@possiblylinux127@lemmy.zip avatar

This is why we need sandboxing. Right now the Linux desktop is still lacking in terms of security

bitterseeds ,
@bitterseeds@fosstodon.org avatar

@possiblylinux127 @wisha And how would sandboxing a malicious script inside a theme that is supposed to change the look of your desktop work? They installed and ran something that rm'd their home directory. I'm honestly curious how you'd solve this.

wisha OP ,

A more locked-down theming API could help. For example Firefox themes are always 100% safe to install. That said, Firefox themes are almost useless (they’re more like color schemes lol), and no one wants to lose KDE’s powerful customizability so 🤷🤷

Canary9341 ,

Perhaps having different categories with different limitations would work well. Using the firefox example, prioritize the use of WebExtensions, but keep XUL/XPCOM with appropriate warnings.

JackGreenEarth ,
@JackGreenEarth@lemm.ee avatar

What do you mean? I have Firefox themes that change the whole look of the browser, using userchrome.css.

https://share.jackgreenearth.org/png/Screenshot-from-2024-03-17-21-55-40.png

HKayn ,
@HKayn@dormi.zone avatar

That’s obviously not what OP was referring to when mentioning “Firefox themes”.

JackGreenEarth ,
@JackGreenEarth@lemm.ee avatar

Maybe, I was showing that there were better ways to theme Firefox though

KomfortablesKissen ,

SELinux? Apparmor? (Serious question, I don’t know if there might be features that render those two inadequate)

possiblylinux127 ,
@possiblylinux127@lemmy.zip avatar

If it ran in a sandbox it would just wipe its own files instead of the system. Under no circumstances should a plugin from some random guy online be running with such high privileges

bitterseeds ,
@bitterseeds@fosstodon.org avatar

@possiblylinux127 I was asking how you’d run something that modded the whole UI … sandboxed.

possiblylinux127 ,
@possiblylinux127@lemmy.zip avatar

You would need to expose some sort of hook that allows modifications

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • [email protected]
  • All magazines