Firewall blocking desktop features

>> >    - This means that any privileged service controlled by GUI client (e.g:
>> >      NetworkManager) is still only as secure as it's controller (e.g:
>> >      nm-applet).
>> This is wrong. That's not how "controlling the service" works.
> Care to explain?

Yes. What I meant is nm-applet is not more privileged then any other
application in the session.
The policy says "the active session is allowed to do foo" not
"nm-applet is allowed to do foo".
So you can securing the "controller" wont help you much as long as any
other app from the active
session can be exploited.

