Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Comparing landlock to containers isn't really an apples to apples comparison. Containers use a bunch of linux security mechanisms together like chroot seccomp and user namespaces to accomplish their goals. Landlock is just another building block that devs can use.

Fun fact: because landlock is unprivleged, you can even use it inside containers; or to build an unprivileged container runtime :)





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: