Hacker News new | ask | show | jobs
by dietr1ch 569 days ago
It must be that by running any program within the nix build sandbox you don't expose your files unless you discover a privilege escalation attack by chance during the reduction process.