Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I do use Gentoo currently, but it's so very hard to keep programs from monitoring what happens in the system via dbus and the only firewall for outgoing connections, OpenSnitch, hard-depends on it. Running every major program in a container is NOT a solution.

So far Linus has kept these things outside the kernel, but he won't live forever.



This is why my daily driver is Qubes OS.


OMG, that's even worse than containers.


By which measure?


Storage occupied, memory, CPU, config complexity, startup time, data transfer, take your pick.


Indeed, security has a price. However the storage requirements are minimal, since different VMs can share the root filesystem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: