Results 1 to 10 of 37

Thread: Why isnt apparmor firefox profile enabled by default?

Hybrid View

  1. #1
    Join Date
    May 2009
    Beans
    27
    Distro
    Ubuntu 9.10 Karmic Koala

    Question Why isnt apparmor firefox profile enabled by default?

    This page https://help.ubuntu.com/community/AppArmor shows how to enable apparmor firefox profile. Why isnt apparmor firefox profile enabled by default? I would postulate that this would be because there must be some limitation by having the profile enabled. If so, what would the limitation be?

  2. #2
    Join Date
    Jan 2008
    Location
    USA
    Beans
    971
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Why isnt apparmor firefox profile enabled by default?

    Quote Originally Posted by jasonmchristos View Post
    This page https://help.ubuntu.com/community/AppArmor shows how to enable apparmor firefox profile. Why isnt apparmor firefox profile enabled by default? I would postulate that this would be because there must be some limitation by having the profile enabled. If so, what would the limitation be?
    Short answer: not everyone has the same needs from Firefox, so enabling the profile by default might "break" Firefox for some people and might be too permissive for others.

  3. #3
    Join Date
    Aug 2008
    Location
    Brazil
    Beans
    12,497
    Distro
    Ubuntu Studio 12.04 Precise Pangolin

    Re: Why isnt apparmor firefox profile enabled by default?

    Quote Originally Posted by rookcifer View Post
    Short answer: not everyone has the same needs from Firefox, so enabling the profile by default might "break" Firefox for some people and might be too permissive for others.
    +1

    For instance, it might break extensions functions.

  4. #4
    Join Date
    Mar 2010
    Beans
    8,249
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: Why isnt apparmor firefox profile enabled by default?

    So, here's the thing; if I enable the AppArmor profile for Firefox and things get messed up can I just disable it and everything will be back to "normal"? Secondly, I don't understand what the default profile is doing; a brief explanation about what it protects/prevents would be nice.
    Thanks in advance

  5. #5
    Join Date
    Jan 2008
    Location
    USA
    Beans
    971
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Why isnt apparmor firefox profile enabled by default?

    Quote Originally Posted by Rubi1200 View Post
    So, here's the thing; if I enable the AppArmor profile for Firefox and things get messed up can I just disable it and everything will be back to "normal"?
    Yes.

    Secondly, I don't understand what the default profile is doing; a brief explanation about what it protects/prevents would be nice.
    Thanks in advance
    There is an apparmor sticky at the top of this forum which explains a lot of this.

  6. #6
    Join Date
    Mar 2010
    Beans
    8,249
    Distro
    Ubuntu 10.04 Lucid Lynx

    Re: Why isnt apparmor firefox profile enabled by default?

    Thanks!
    I will check out the sticky as well.

  7. #7
    Join Date
    Jan 2009
    Beans
    61

    Unhappy Re: Why isnt apparmor firefox profile enabled by default?

    Quote Originally Posted by rookcifer View Post
    Yes.

    There is an apparmor sticky at the top of this forum which explains a lot of this.
    Nope. I cannot see a sticky thread about AppArmour in :
    Ubuntu Forums > The Ubuntu Forum Community > Main Support Categories > Security Discussions . However, I won't discount the possibility that I am partially blind.

  8. #8
    Join Date
    May 2009
    Beans
    27
    Distro
    Ubuntu 9.10 Karmic Koala

    Re: Why isnt apparmor firefox profile enabled by default?

    [QUOTE=Rubi1200;9172716]Secondly, I don't understand what the default profile is doing; a brief explanation about what it protects/prevents would be nice.
    Well if fiefox is exploited someone may want to read the password files on the system using a Firefox exploit in attempts to crack them and gain access to your system. Skype for instance does this by default, the skype software is programmed to probe all of the sensitive areas on your system, however I found that the apparmor extra profile that is supposed to keep skype in line renders the current version of skype unusable. Looks like i will have to actually make my own profile. In short the firefox profile puts restrictions on what firefox can do. I am not sure of the exact details yet since i havent got too deep into apparmor yet. I heard through the grapevine that canonical intends to abandon apparmor for selinux. Not sure if I should be spending a lot of time on learning apparmor.

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •