Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If Theo stopped being so resistant to solutions like AppArmor, then OpenBSD could have a real security layer instead of toys like unveil and pledge.


Here is Justine's write up on pledge and why he wants to port it to Linux. https://justine.lol/pledge/


It has its uses I guess, but it requires opt-in which is a pretty big disadvantage, and then still can't do even a fraction of what SELinux can already do. SELinux isn't that hard to learn, and the security benefits are immense.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: