Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
gwicke
on Aug 7, 2016
|
parent
|
context
|
favorite
| on:
Firejail – security sandbox
At Wikimedia, we are using firejail to lock down services. We encountered some bugs in older versions, but those have since been fixed. Overall, it has been working fairly well for us.
Scaevolus
on Aug 7, 2016
[–]
What made you choose Firejail over alternatives like Docker?
microtonal
on Aug 7, 2016
|
parent
|
next
[–]
Or maybe even more appropriate: AppArmor (or SELinux).
dingaling
on Aug 7, 2016
|
root
|
parent
|
next
[–]
Firejail can be invoked and configured by normal unprivileged users. Apparmor requires root for creating and installing new profiles.
feld
on Aug 7, 2016
|
root
|
parent
|
prev
|
next
[–]
The new tools are being invented because the old tools suck.
SELinux is terrible from a UX standpoint
mynewtb
on Aug 7, 2016
|
parent
|
prev
[–]
Docker is not for secure sandboxing, afaik you can easily escape and get root.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: