Comment by truetraveller
2 hours ago
I want a super-simple way to restrict an app's read/write to a specific dir. This is an incredibly useful solution that should have existed 20+ years ago. Why is this not a thing? This will basically solve most security issues immediately, in a super user-friendly way.
I don't believe this is what MXC accomplishes. Happy to be told otherwise!
You can launch arbitrary executables with MXC but different backends provide different security guarantees. Some backends like LPAC on Windows cause many exes to straight up fail during startup (powershell for instance)