linux isnt immune to viruses even though its not as bad as windows

what should i do to be safe if i have a safe browser, vm, but pirate and download risky things? i know its a vm but i still dont want to have to delete everything in the vm if something happens. also the malware doesnt go to the router and spread rigt???

    • Vittelius@feddit.org
      link
      fedilink
      arrow-up
      7
      ·
      20 days ago

      And if you need an app from a third party repo, pick one that includes at least rudimentary sand boxing such as flatpak/flathub

      • ShankShill@sh.itjust.works
        link
        fedilink
        arrow-up
        4
        ·
        20 days ago

        And if you pegleg some games, there’s an ice cream-loving wrestler (or maybe some folk that just borrowed the id) that tend to bubble wrap their warez.

        If it says no network access, my Wireshark says no network is being accessed. That’s all the confirmation I got.

      • Linearity@piefed.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        17 days ago

        Flatpak is missing even rudimentary sandbox features. Apps that don’t have an easy sandbox escape are rare. And this is all useless when it’s the app developer who decides the app permissions because most users won’t tinker with every Flatpak they install.

        Flatpaks are NOT any more secure than system packages, and their “sandboxing” should not be trusted to accomplish anything.

        • dieTasse@feddit.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          3 hours ago

          The permissions have to be justified when uploading to flathub (via PR) and the exceptions are not always accepted. Flatpaks ARE safer than system packages and if you think otherwise I recommend you taking a look who can access all passwords on the keyring and who doesn’t. (Getting such exception on flarhub is very hard). Flatpak 2.0 hopefully gets user approvals for permissions. But still with current flatpak you have the option to reject permission via flatseal.