zlacker

[parent] [thread] 0 comments
1. senko+(OP)[view] [source] 2026-02-03 20:59:24
No disagreement from me. From the article:

> Bubblewrap and Docker are not hardened security isolation mechanisms, but that's okay with me.

Edit to add: my understanding is the major flaw in this approach is potential bugs in Linux kernel that would allow sandbox escape. Would appreciate your insight if there are some easier/more probable attack vectors.

[go to top]