- Jul 3, 2015
- 8,153
that sounds interesting. could you explain the difference?Inability to execute and isolation are two different things; incorrect terminology.
Does isolation imply inability even to read the files?
that sounds interesting. could you explain the difference?Inability to execute and isolation are two different things; incorrect terminology.
that sounds interesting. could you explain the difference?
Does isolation imply inability even to read the files?
okay, so let's say for example that I "upgrade" from voodoo's browser application control, and instead I go for browser isolation, ala comodo sandboxed browser or rehips browser user profile.Anti-executable is application control.
Isolation is whereby a program is denied or given only restricted access to the real user profile, file system, registry, etc - with or without virtualization. Depending upon the soft (COMODO, ReHIPS, Sandboxie, SpS, most HIPS) you can set access rights to be as restrictive or as loose as you like. In COMODO, for just an example, you can deny read\write (complete) access to folders and files. Same can be achieved identically or similarly in other softs. What and how varies from one soft to the other.
Software restriction policy softs likewise can restrict access to file system and registry plus control program and file type execution.
Softs that use virtualization (Sandboxie, COMODO, Shadow Defender, etc) replicate the file system and registry inside a virtual container. Any modifications are made to the virtualized file system and registry and those changes are non-permanent unless you make exceptions or "commit" the changes to the real user profile. ReHIPS does not use virtulization, but instead relies upon Windows' built-in protection mechanisms via separate user profiles. Each user profile cannot access another user profile - which is true isolation.
okay, so let's say for example that I "upgrade" from voodoo's browser application control, and instead I go for browser isolation, ala comodo sandboxed browser or rehips browser user profile.
what did I gain in security?
okay, but if there is application control on the browser, how will a compromised browser be able to mess with your user files, even if it theoretically has access to them?Real user profile is not compromised by malware with isolation.
okay, but if there is application control on the browser, how will a compromised browser be able to mess with your user files, even if it theoretically has access to them?
these are awesome explanations. I am running out of questions!
On my laptop, I use basic user setting in SRP (Windows 10 Pro) along with EMET, ublock origin, Netcraft (only xss protection ticked) and Windows Defender. Of course flash is click to play set in browser. I think this conf. is enough good too for browser exploits. If I want to visit specifically risky websites, I use SBIE for Chrome but for general browsing I don't.Your security config does not need to be complicated; a relatively simple config can provide very good baseline security.
Voodooshield and Reboot Restore RX or Rollback RX Home (both freeware) would work nicely. Add a decent adblocker (uBlock Origin as an example) and TinyWall (or similar) and your config is quite solid without heavily impacting your system.
From being here at MT you should already have a good idea of the more popular effective security soft combos.
On my laptop, I use basic user setting in SRP (Windows 10 Pro) along with EMET, ublock origin, Netcraft (only xss protection ticked) and Windows Defender. Of course flash is click to play set in browser. I think this conf. is enough good too for browser exploits. If I want to visit specifically risky websites, I use SBIE for Chrome but for general browsing I don't.
Correct me if I m wrong.
Indeed, the attack comes the time you least expect it. My problem with SBIE is that lately it has some problems with Chrome and error/warning messages appear out of the blue while browsing. I cannot figure out the exact cause.It's a sound config, but why not do all general browsing in Sandboxie ? - because during general browsing your browser and system are still at risk. The websites you think are safe are more than likely prone to attack through negligence or improper security configs - and you have no way of knowing it until it is too little too late. A browser attack will happen when you least expect it... but, I will admit, with a fully updated browser the risk is small. I assume you have your browsers properly configured in EMET and with Flash click-to-play so that diminishes the risk even further. Just something to think about... that's all.
It looks good... well thought out config.
Indeed, the attack comes the time you least expect it. My problem with SBIE is that lately it has some problems with Chrome and error/warning messages appear out of the blue while browsing. I cannot figure out the exact cause.
Is there any free reliable solution (or <10$) to sandbox google chrome?That's why I no longer mess with SBIE; Windows updates, browser updates or certain browsers always causing issues - until Invincea fixes them - which isn't always a fast process. In my experience the problems creep up on a fairly consistent base so for me it is more than a mere annoyance but a real interference.
Is there any free reliable solution (or <10$) to sandbox google chrome?
but keep in mind that ReHIPS free version cannot run chrome isolated.
I used to use Comodo for such reasons, but I prefer not to mes with such a big package that contains other features too.. but I will think of it as the only alternative.My goof...
A soft that is somewhat similar in concept, but not technically the same is ReHIPS.
- Comodo Internet Security
- Comodo Cloud Antivirus
You might want to take a look at Rollback RX Home and Reboot Restore RX - both freeware. Both are worthy of consideration.
CCAV is their smallest package, but it's still a package...I used to use Comodo for such reasons, but I prefer not to mes with such a big package that contains other features too.. but I will think of it as the only alternative.
Because of the 10 processes limit of the demo. The full version does it perfectly. In theory if you don't use a lot of tabs or extensions you can use chrome but i must agree it's hard.but keep in mind that ReHIPS free version cannot run chrome isolated.