logoalt Hacker News

ethanwillistoday at 8:58 AM3 repliesview on HN

What we need is a capabilities based security system. It could write all the python, asm, whatever it wants and it wouldn't matter at all if it was never given a reference to use something it shouldn't.


Replies

mcvtoday at 9:20 AM

Isn't this already possible? Give it its own user account with write access to the project directory and either read access or no access outside it.

show 2 replies
rienbdjtoday at 1:19 PM

Docker is enough in practice no?

diablevvtoday at 2:02 PM

[dead]