Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> is actually one of the least secure OSes out there

Linux is one of the most secure platforms to run web applications on, however, because more man hours than I can comprehend were spent hardening that use case.

All of those hardening measures can transfer over to the Linux desktop use case.

For example, seccomp, cgroups and MAC can all be used to harden a Linux server, and they can also be used to harden the Linux desktop. It's just that no one has thrown the same billions of dollars at desktop Linux that were thrown at solving web application security.

If you really wanted to, you could run a lot of your software in unprivileged containers secured with seccomp.



>If you really wanted to, you could run a lot of your software in unprivileged containers secured with seccomp.

We've come full circle, because Snap does run software in unprivileged containers.


They are not the same thing, however, and the complaints people have about Snap don't stem from its use of unprivileged containers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: