Hacker News new | ask | show | jobs
by noobquestion81 1775 days ago
actual bugs, qualys’s recent cve-2021-33909 is one example.
1 comments

To clarifymy stance, now that I have a bit more time this evening… unprivileged userns is the only way forward for linux sandboxing on a bare-metal host past the boundaries of POSIX isolation. so from a security perspective I do hope most distros get this turned on at some point, and that these bugs stop being so commonplace.