3 ms·
The real reason behind isolated systemd services is to confine the damage if a world-accessible daemon gets breached. If your threat model is you can't trust t
by tagrun 8y ago
The real reason behind isolated systemd services is to confine the damage if a world-accessible daemon gets breached.
If your threat model is you can't trust the programs running on your computer, then maybe you should switch to a different OS, for example Debian, and stick to the package manager.