Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Using a container sandbox such as gvisor would definitely help. Or even using firejail for normal systemd processes


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: