If I sandbox an application, can the application take a screenshot of my desktop or something?
See:
https://firejail.wordpress.com/documentation-2/x11-guide/
The short answer is: this is not prevented by default settings, but it can be prevented.
Wayland: #3148
@jonleivent The link is named after the correct target, but if you click it, you go somewhere else.
@heinrich5991 That's a strange effect! All I did was paste the link. I'll try again with markdown:
https://firejail.wordpress.com/documentation-2/x11-guide/
It did it again. That's truly strange. Will it do it as quoted text?:
OK - that worked.
Without the [ and the ](url) it works. Original:
> See:
> [https://firejail.wordpress.com/documentation-2/x11-guide/](url)
>
> The short answer is: this is not prevented by default settings, but it can be prevented.
BTW - I think --x11=xorg, when the app can handle it, is sufficent to screenshooting. It doesn't prevent as much potential X spying as xephyr or xpra, though. Also, an attempt to do screenshooting with --x11=xorg will generate an X11 error for the app, while with xephyr and xpra the app will take a picture of its restricted screen.
I'm closing here because the question is answered.
Most helpful comment
Wayland: #3148