←back to thread

441 points longcat | 2 comments | | HN request time: 0s | source
Show context
vorgol ◴[] No.45039050[source]
OSs need to stop letting applications have a free reign of all the files on the file system by default. Some apps come with apparmor/selinux profiles and firejail is also a solution. But the UX needs to change.
replies(5): >>45039375 #>>45040698 #>>45041459 #>>45041809 #>>45045968 #
1. anthk ◴[] No.45041459[source]
Learn to use bubblewrap with small chroot.
replies(1): >>45042486 #
2. eyberg ◴[] No.45042486[source]
Bubblewrap has refused to fix known security issues in its codebase and shouldn't be used.