Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
NewJazz
1y ago
0 comments
Share
If it is running as root, can't it just manipulate its mount namespace at will? Mount devtmpfs, then mount user partitions.
0 comments
default
newest
oldest
hackernudes
1y ago
I believe one can use "capabilities" and seccomp to lock down a superuser process.
superb_dev
1y ago
Systemd can put it in its own namespaces, like a container
j
/
k
navigate · click thread line to collapse