Sandboxing and system separation
Can you protect your system from a misbehaving program?
By .default, Snap packages have little access to the alternative directory and run it from there. system. The package creators themselves are able to switch on certain access to resources. Furthermore, the user mode tools for managing Snaps allow refinement of these options. For example, the Snap Store allows users to switch the permissions of an application on and off to access the network, audio facilities and the home folder, among other resources.