Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do not make it easy to disable the sandbox, but keep the user in control.

Linux evades a huge amount of virus and phishing just because you have to `chmod +x` stuff before running, for example. A "Software wants to do nasty stuff. Allow | Disallow" prompt just does not make it.

Also, users will want to piece the sandbox some times, do not make it an all or nothing situation. Make giving common permissions easy, rare permission hard, and give fine grained control over them.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: