zlacker

[parent] [thread] 0 comments
1. kijiki+(OP)[view] [source] 2017-11-19 20:04:19
https://cappsule.github.io/

It's unmaintained now, but it is basically the same idea as WDAG. Essentially similar to firejail but the container gets its own lightweight kernel and runs in a stripped down VM, so the attack surface is KVM, not all parts of the kernel that aren't firewalled off by SECCOMP.

[go to top]