3 ms·
This approach is stupid. That's like relying on criminals to cuff themselves when they have committed a crime.
by imcritic 10mo ago
This approach is stupid.
That's like relying on criminals to cuff themselves when they have committed a crime.
- woodruffw 10mo agoThat’s not how userspace sandboxing works. The assumption is that privilege flows from a trusted parent process to an untrusted child, so the trusted parent is the one responsible for setting the access controls.
- tremon 10mo agoNot really. It's more like wearing seatbelts: the car is not supposed to crash, but in case something unforeseen happens, please don't let the passengers exit through the windshield.