2 ms·
To a degree, everything can be exploited, for sure. Memory safety always remains an issue. The sandboxing I was referring to however was the sandboxing from arb
by Deukhoofd 2y ago
To a degree, everything can be exploited, for sure. Memory safety always remains an issue. The sandboxing I was referring to however was the sandboxing from arbitrary syscalls. While some operating systems have functionality to do so (for example OpenBSD's pledge), this is unfortunately still very much a niche feature.
Containers solve this problem to a degree, but running GUIs or plugins within them is non-trivial for end users.