4 ms·
Well, the boundary between the host and the guest, the system call API, is always going to be the biggest vector of attacks no matter what the solution used is.
by fwsgonzo 2y ago
Well, the boundary between the host and the guest, the system call API, is always going to be the biggest vector of attacks no matter what the solution used is. But, if you find a problem and fix it, you're back to being safe again, unlike if you don't have any sandboxing at all. You can also put the whole solution in a jail, which is very common nowadays.
- jumploops 2y agoCan you expand on “put the whole solution in a jail”?
- fwsgonzo 2y agoFireCracker has a jailer: https://github.com/firecracker-microvm/firecracker/blob/main/docs/jailer.md https://github.com/firecracker-microvm/firecracker/blob/main...
- jumploops 2y agoAh, this is helpful, thanks!
- CartwheelLinux 2y agohttps://wiki.freebsd.org/Jails https://wiki.freebsd.org/Jails