Skip to content

Comment on FreeBSD Capsicum vs. Linux Seccomp Process Sandboxing

Comments

subtraction vs filtration is the right framing even if the article is slop. removing capabilities is structurally different from filtering syscalls because the set of things to filter grows every kernel release but the set of things a process actually needs doesn't.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.