Conversation

Anyone have experience with Anbox? Does it properly sandbox apps? Does it senselessly depend on a glibc host or particular container runtimes? Can you easily do one app per sandbox, or only whole Android? anbox.io
2
Replying to
It doesn't provide meaningful sandboxing and doesn't approach it the way that you want. Their comparison to the Android integration in ChromeOS is also wrong / misleading. You're better off using the Android emulator for a KVM / QEMU based VM without everything hacked together.
2
Replying to and
Using the standard VM approach isn't substantially more heavyweight. It performs well and is much more robust and compatible. ChromeOS isn't currently using virtualization for performance reasons but they really should be doing it that way. As is, it turns ChromeOS into Android.
2
Replying to and
There's not really that much difference between using Android with Chrome in the app sandbox or using ChromeOS with Android inside a container. The kernel is the same, verified boot and update system is comparable, and security between apps and Chrome is essentially the same too.
2
Replying to
Namespaces can be a tight sandbox. Also if stuff is setup to be able to run in a namespace container you can just as easily run it in a fully ptraced container with no access to any real syscalls.
2