logoalt Hacker News

nextos11/09/20241 replyview on HN

For me the interesting part of Firejail is the interface. bwrap is usually recommended as a replacement given that the binary is smaller and thus offers less attack surface, which I think is the usual concern. Firejail employs kernel user_namespaces, but also offers integration with AppArmor.


Replies

hollerith11/09/2024

>the binary is smaller and thus offers less attack surface, which I think is the usual concern.

Another concern is the huge attack surface that is the Linux kernel.

show 1 reply