On Thu, 15 May 2014 20:35:41 +0200 "Thomas D." <[email protected]> wrote: > Ciaran McCreesh wrote: > > Sandboxing isn't about security. It's about catching mistakes. > > From Wikipedia > (http://en.wikipedia.org/wiki/Sandbox_%28computer_security%29): > > In computer security, a sandbox is a security mechanism for > > separating running programs. It is often used to execute untested > > code, or untrusted programs from unverified third-parties, > > suppliers, untrusted users and untrusted websites > > network-sandbox is using unshare() syscalls to separate... not?
Not for security reasons: sandbox (the way it is used on Gentoo) does nothing against a malicious ebuild or a malicious package. Instead, it simply catches certain common mistakes. -- Ciaran McCreesh
signature.asc
Description: PGP signature
