Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At Wikimedia, we are using firejail to lock down services. We encountered some bugs in older versions, but those have since been fixed. Overall, it has been working fairly well for us.


What made you choose Firejail over alternatives like Docker?


Or maybe even more appropriate: AppArmor (or SELinux).


Firejail can be invoked and configured by normal unprivileged users. Apparmor requires root for creating and installing new profiles.


The new tools are being invented because the old tools suck.

SELinux is terrible from a UX standpoint


Docker is not for secure sandboxing, afaik you can easily escape and get root.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: