On Thu, 15 May 2014 20:35:41 +0200
"Thomas D." <[email protected]> wrote:
> Ciaran McCreesh wrote:
> > Sandboxing isn't about security. It's about catching mistakes.
> 
> From Wikipedia
> (http://en.wikipedia.org/wiki/Sandbox_%28computer_security%29):
> > In computer security, a sandbox is a security mechanism for 
> > separating running programs. It is often used to execute untested 
> > code, or untrusted programs from unverified third-parties,
> > suppliers, untrusted users and untrusted websites
> 
> network-sandbox is using unshare() syscalls to separate... not?

Not for security reasons: sandbox (the way it is used on Gentoo) does
nothing against a malicious ebuild or a malicious package. Instead, it
simply catches certain common mistakes.

-- 
Ciaran McCreesh

Attachment: signature.asc
Description: PGP signature

Reply via email to