Hacker News new | ask | show | jobs
by containedgravel 667 days ago
>Linux distributions do not implement it out of the box

There are several distributions that _do_ implement by-default restrictions to all running software with stuff like Cgroups and GRSecurity. There are even distributions dedicated to isolating even the drivers, like Qubes.