Ideally I would like to just run a command that does it all for me, passing the binary I want to run through that, like:
"sandbox firefox"
The other ways are hassle:
https://wiki.archlinux.org/index.php/Sk ... ecial_user
http://mancoosi.org/~abate/running-skype-a-schroot
Easy on Windows... but unstable:
http://www.sandboxie.com/index.php?FirefoxTips
QEMU is an option but that I think is too heavyweight and overkill. Same for SELinux. Apparmor isn't available.
It's not just about practicalities of protecting Skype, Steam for Linux, Chromium apps and other closed source stuff that are surely going to become more commonplace over time. It's the beauty of getting something right. Like polishing underneeth the bonet of a car. I really find the idea of running everything as a single administrator user most unlinux-like and untidy - stinks of Winbloze, especially now Chrome & Android sandbox without much user intervention these days.
