Hacker News new | ask | show | jobs
by bluetech 3175 days ago
systemd should have a "whitelist" mode, where everything is locked down by default. Or at least, some /usr/share/doc/systemd/locked-down-example.service file with all of the relevant options set to "secure mode". It can be hard to follow all of the new features :)