#How to use Bubblejail?

1 messages Β· Page 1 of 1 (latest)

obsidian spade
#

I can't really find any instructions on how to use bubblejail. I have created an instance via the UI but I don't know how to add a program to that instance.

gentle swan
#

I assumed all programs were already bubblejailed, or am I wrong to assume that..?

obsidian spade
tender ledge
#

bubblejail is preinstalled for convenience, but it doesn't even work ootb

#

as it requires unprivileged, unconfined user namespaces

#

which are a security risk

gentle swan
gentle swan
#

hm I see, well it's still good to have all the other security things

tender ledge
#

your best bet is to move as much as possible to a model resembling android

#

"lock down" the system, and use applications that are sandboxed

#

also I should mention @gentle swan that Trivalent isn't sandboxed per se but is relatively strongly confined by SELinux

#

so if something isn't a flatpak, using a Trivalent PWA is a good option

gentle swan
#

oh, good to know, thank you

gentle swan
#

I just hope a Discord PWA would have the same notifications as the desktop app
and that they wouldn't be muted

tender ledge
#

the policy if you're interested^

gentle swan
#

not even if you manually enable notifications for the Discord website?

tender ledge
#

oh

#

then it might

#

idk

#

i keep notifs off πŸ˜„

#

otherwise it would be buzzing all day

gentle swan
#

yeah I'll try it out tomorrow when I finally get the time to install Secureblue for real

gentle swan
obsidian spade
tender ledge
#

the unverified flatpak may be preferable

#

it depends

obsidian spade
tender ledge
# obsidian spade on?

on what you're trying to protect against and whether you're comfortable subscribing to and reading changes to the unverified flatpak manifest

#

in general I'd personally prefer the unverified flatpak

#

it also depends on the app

#

as for some app there is no "verified" way to use it at all on fedora

#

like steam

#

whether you use the rpm, the arch package, or the flatpak, it's all unverified

#

because valve only publishes a deb

obsidian spade
# tender ledge on what you're trying to protect against and whether you're comfortable subscrib...

As I'm not really an IT person, I don't think I will get much from reading the flatpak manifest. I would just prefer what is generally the safest option. I'm planning to install this https://apps.ankiweb.net/#downloads And the flatpak here seems to be community built https://flathub.org/apps/net.ankiweb.Anki

I personally don't have the expertise to judge what's the better option, that's why I'm asking

Flathub - Apps for Linux

Powerful, intelligent flash cards

obsidian spade
#

@tender ledge ?

tender ledge
vital remnant
#

Wouldn't something like this help you ?

#
tender ledge
#

but it would be best with a degree of checking the flatpak manifest

obsidian spade
#

Alright, thanks for the help

vague relic
#

It's on flathub

gentle swan
# vague relic GoofCord is good

I've been told that even Discord's official flatpak client is less secure than a Discord PWA, so Goofcord is probably the same

brazen horizon
#

Yeah, ideally use the official client for the best functionality, or the PWA for security, everything else sacrifices one of these two or both, also risks your account

tender ledge
#

and with the pending IPO i suspect they might start changing their tune on that

vague relic
vague relic
brazen horizon
#

so does the PWA

#

since Trivalent does

vague relic
#

I did this with Bitwarden

#

I'm using the Web vault and the Extension

#

Because Bitwarden Flatpak client is just X11

#

Sadly

#

A password manager without screen protection

#

"A secure and free password manager for all of your devices"

#

For me it's just really secure on Android

brazen horizon
#

same goes for most messengers as well

vague relic
#

Yeah

#

But the password manager is even more sensitive

#

At least the extension has his beauty

#

Is this setup safe? How much an profile/user on Chromium is isolated?

#

I called this profile "Vault", but how much is it? Lol

brazen horizon
#

what are trying to prevent by using multiple profiles?

#

a website exploiting the extension?

vague relic
#

I don't want websites I navigate seeing this extensions

brazen horizon
#

they can't, just disable the extension's access to those sites

brazen horizon
#

or block general site access and make it click-to-allow

vague relic
#

The first time I open the website will see the extension

#

Just like Incognito accessed will be "protected" in this case

brazen horizon
#

websites only see the extension if the extension makes it's presence known, or an exploit in the engine which is a bigger issue

vague relic
#

Using multiple profiles seems not useful to you?

vague relic
tender ledge
brazen horizon
brazen horizon
vague relic
brazen horizon
vague relic
#

Yea

#

Because I do this on Android

#

For example

#

So I have this need to isolate things

#

It's already part of how I organize my digital life