| ▲ | nobody42 an hour ago | |
Memory safety is good, but does not protect from every threat. In this day and age infrastructure operators should familiarize themselves with proactive defenses, MAC: SElinux and AppArmor. It required much friction earlier, but there are more tools to ease the usage today. https://presentations.nordisch.org/apparmor/ https://github.com/nobody43/apparmor-profiles/blob/master/ng... https://github.com/nobody43/apparmor-suggest Disclaimer: I'm the author of both repos. | ||