← Back to context

Comment by 0c3ca83

1 hour ago

That seems like a massive hole in the model that would make it very hard to lock down multi-process/privsep programs like sshd.

Sandboxing something like that is challenging, yes. But probably not for this reason you can always disclaim responsibility for your process.