logoalt Hacker News

ajbyesterday at 4:03 PM0 repliesview on HN

Theoretically, they have a smaller attack surface. The programs inside the VM can't interact directly with the host kernel.