logoalt Hacker News

0c3ca83 • today at 2:16 AM • 1 reply • view on HN

That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.


Replies

saagarjha • today at 2:23 AM

Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.

➕ show 1 reply