Author

Topic: Could You Use "Sandboxie" To Run Your Client? (Read 1860 times)

hero member
Activity: 812
Merit: 1000
September 02, 2013, 09:24:27 AM
#8
Wrong again. Sandboxie is humble attempt to prevent stuff from making permanent changes to PC instead of preventing it from accessing data on host filesystem or phoning the data from host computer to remote server. I experimented a lot with sandboxie and found the whole idea totally useless. For isolation of dangerous processes full virtualization like VMware Workstation is required. And virtualization will not protect secrets in event when host operating system is compromised by malware.

Do malicious processes escape the sandbox or make permanent changes to the system? No. That's what Sandboxie is for.

If you don't want malware recording keystrokes or calling home, don't leave it open in Sandboxie.

Of course, there are better ways, but I think Sandboxie is still useful in some cases.

i think what mysteryminer meant is that on a malware-compromised host, the actual sandboxie exe might be compromised, and do all sorts of nasty things that 'regular' sandboxie wouldn't do, including let certain malicious processes escape and make permanent changes to the host.

b!z
legendary
Activity: 1582
Merit: 1010
September 02, 2013, 09:18:46 AM
#7
Wrong again. Sandboxie is humble attempt to prevent stuff from making permanent changes to PC instead of preventing it from accessing data on host filesystem or phoning the data from host computer to remote server. I experimented a lot with sandboxie and found the whole idea totally useless. For isolation of dangerous processes full virtualization like VMware Workstation is required. And virtualization will not protect secrets in event when host operating system is compromised by malware.

Do malicious processes escape the sandbox or make permanent changes to the system? No. That's what Sandboxie is for.

If you don't want malware recording keystrokes or calling home, don't leave it open in Sandboxie.

Of course, there are better ways, but I think Sandboxie is still useful in some cases.
hero member
Activity: 812
Merit: 1000
Additional layers of encryption inside this full disk one are pointless, it degrades convenience and performance with no real additional security.

well duh, but like you know, i never said anything about 'additional', because i don't do WDE.
legendary
Activity: 1512
Merit: 1049
Death to enemies!

and keep all your vmware or virtualbox images inside truecrypt containers

Why? If my host OS is compromised everything is goatsed. I use full disk encryption in case of hardware theft. Additional layers of encryption inside this full disk one are pointless, it degrades convenience and performance with no real additional security.
hero member
Activity: 812
Merit: 1000
For isolation of dangerous processes full virtualization like VMware Workstation is required. And virtualization will not protect secrets in event when host operating system is compromised by malware.

and keep all your vmware or virtualbox images inside truecrypt containers
legendary
Activity: 1512
Merit: 1049
Death to enemies!
Wrong again. Sandboxie is humble attempt to prevent stuff from making permanent changes to PC instead of preventing it from accessing data on host filesystem or phoning the data from host computer to remote server. I experimented a lot with sandboxie and found the whole idea totally useless. For isolation of dangerous processes full virtualization like VMware Workstation is required. And virtualization will not protect secrets in event when host operating system is compromised by malware.
legendary
Activity: 1288
Merit: 1227
Away on an extended break
Nah, Sandboxie's more geared towards keeping stuff from getting out from the box then to keeping stuff from getting in. 
sr. member
Activity: 302
Merit: 250
Would "Sandboxie" be  an option to be secure and safe?

http://www.sandboxie.com/
Jump to: