Hacker News new | ask | show | jobs
by blattimwind 2705 days ago
> Priv-sep

Apt even has the had part already implemented by separating the network I/O in other processes. Only problem is that those currently write directly to system directories, but that can be fixed.