Hacker News new | ask | show | jobs
by mhall119 3428 days ago
Snaps need a security backend like AppArmor in order to run in confinement. Without it, they can still be run unconfined. And while AppArmor+seccomp is the only working security backend, snapd is designed to support alternate backends, so one could be made for SELinux, we just need someone with SELinux experience to write it (our in-house expertise is in AppArmor)