| ▲ | senko 3 hours ago | |
No disagreement from me. From the article: > Bubblewrap and Docker are not hardened security isolation mechanisms, but that's okay with me. Edit to add: my understanding is the major flaw in this approach is potential bugs in Linux kernel that would allow sandbox escape. Would appreciate your insight if there are some easier/more probable attack vectors. | ||