Your distro already has AppArmor files for your distro software.
You can also kick it into learning mode if you desire.
You could also just stick to flatpaks/snaps - totally sandboxed.
You could choose Whonix where every app is an isolated VM.
Or choose tails where any egress is locked down and monitored.
Your distro already has AppArmor files for your distro software.
You can also kick it into learning mode if you desire.
You could also just stick to flatpaks/snaps - totally sandboxed.
You could choose Whonix where every app is an isolated VM.
Or choose tails where any egress is locked down and monitored.