Skip to content

Comment on Show HN: Sandy – A tiny Sandbox to run untrusted code ️parent

Comments

craigOP

Yeah, "sandbox" is definitely a stretch, but I couldn't think of a similar but descriptive term. I've also found since posting there are definitely some easy to expose security wholes where the syscalls aren't traced in threads and child processes. So there is lots of room for improvement. I'll take a look at the projects you mentioned to see how they've tackled those issues. Thanks!

"Sandboxing" and "untrusted code" usually carry security connotations. I'd suggest you advertise this as instrumentation or tracing instead.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.