Hacker News new | ask | show | jobs
by dogfu 5349 days ago
sigh

Does that include the sandbox itself, which was written in C?

2 comments

Yes? But it presents a much smaller attack surface (as compared to the attack surface presented by the set of applications you might otherwise run under a sandbox). And it's maintained/secured by one vendor instead of the set of vendors that distribute the applications you might otherwise run under the sandbox.
Ah, but the sandbox profile are written in scheme! So clearly all good.