Hacker News new | ask | show | jobs
by mirashii 2 hours ago
That would be why it chose a VM that is explicitly designed for sandboxing rather than native executable code or similar, the risk can be minimized by reducing the surface area available to that executable code to almost nothing.