logoalt Hacker News

hollerith11/09/20241 replyview on HN

>the binary is smaller and thus offers less attack surface, which I think is the usual concern.

Another concern is the huge attack surface that is the Linux kernel.


Replies

fpoling11/09/2024

Firejail attempts to mitigate that with secomp filters.