Hacker News new | ask | show | jobs
by capitol_ 570 days ago
How does this protect against dangerous things?

My understanding is that this would just cause the dangerous things to be repeatable.

1 comments

It must be that by running any program within the nix build sandbox you don't expose your files unless you discover a privilege escalation attack by chance during the reduction process.