logoalt Hacker News

Razengantoday at 7:35 PM4 repliesview on HN

Also, operating systems should let us set filesystem permissions per app/process/executable instead of just user accounts.

Similar to how macOS/iOS Sandboxing works but at a more lower and granular level


Replies

Retr0idtoday at 7:45 PM

SELinux is basically this.

show 1 reply
strbeantoday at 8:32 PM

https://www.canyonroad.ai/ does some of this in a way tailored to agents.

pianopatricktoday at 9:09 PM

personally I wish the OS would allow syscall filtering per user

Jhatertoday at 7:40 PM

[dead]