Hacker News new | past | comments | ask | show | jobs | submit login

> these tools often use a setuid binary, which actually has more permissions than most users.

These tools often drop privileges as soon as the program is executed, in firejail, there's also an option to disalble root entirely within a namespace.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: