[−]truetraveller · 2026-10-10 Sat 20:29 UTC ·
link
I want a super-simple way to restrict an app's read/write to a specific dir. This is an incredibly useful solution that should have existed 20+ years ago. Why is this not a thing? This will basically solve most security issues immediately, in a super user-friendly way.
I don't believe this is what MXC accomplishes. Happy to be told otherwise!
You can launch arbitrary executables with MXC but different backends provide different security guarantees. Some backends like LPAC on Windows cause many exes to straight up fail during startup (powershell for instance)
[−]truetraveller · 2026-10-11 Sun 00:07 UTC ·
link
I don't want to care about backends or whatever! And I wrote a programming lang / IDE / high-perf database. Imagine a "normal" user! Why the over-engineering? Thanks for the info, btw!
Docker Sandboxes are just that. The default file access is just the directory you create the sandbox under. They lock down most network access also, with whitelisting of domains and a firewall.
I don't believe this is what MXC accomplishes. Happy to be told otherwise!