Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or use ‘chroot’. Or run it as a restricted owner with ‘chown’. Your grandparents solutions to these problems still work.


That'll still allow access to env vars, and interact with other processes owned by the same user.

At the very least, you really need to add process isolation / namespacing as well - at which point it's going to be easier to just use the sandboxing / containerisation tool of your choice to manage it all for you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: