Hacker News new | past | comments | ask | show | jobs | submit login

sigh

Does that include the sandbox itself, which was written in C?




Yes? But it presents a much smaller attack surface (as compared to the attack surface presented by the set of applications you might otherwise run under a sandbox). And it's maintained/secured by one vendor instead of the set of vendors that distribute the applications you might otherwise run under the sandbox.


Ah, but the sandbox profile are written in scheme! So clearly all good.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: