Hacker News new | ask | show | jobs
by ay1n 4196 days ago
I think sandboxing is a quite good solution, but it doesn't mean that you can't have a root access. Consider jails in FreeBSD, where you can isolate a single process but at the same time you have a control over whole system.

Your car analogy can provide insight into the consequences of a single insecure system in the network, but at the same time it's not valid when you consider that you can (should) control your systems and network if it has to fit your needs.