For the best experience on desktop, install the Chrome extension to track your reading on news.ycombinator.com
Hacker Newsnew | past | comments | ask | show | jobs | submit | history | fonder's commentsregister

> it may hurt more than it helps.

If we use a web browser as an example, what are the odds that a compromised website is going to try to exploit the browser itself vs. exploiting an external sandbox application? Clearly the former. Sandboxing a web browser will prevent many more classes of attack than it exposes you to.

Also worth noting that the suid binary you mention will refuse to run at all if the executing user isn't in its whitelist. It's not like you can pop a shell on some ftp user and run firejail as root.


You're assuming escaping the browser sandbox wouldn't also escape the firejail sandbox. The bypasses are likely the same.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search:

HN For You