Comment by codedokode

4 hours ago

Is "firejail" a white list (only these things allowed) or black list solution (everything not explicitly disallowed is allowed)? I glanced through the issues and it seemed to me it is very hacky and feels amateur-ish and doesn't make me trust it, so I am starting writing my own, white-list based sandboxes. For example, No-net Sandbox will not allow a single packet out, including DNS query, unless allowed, Proc Sandbox will restrict access to /proc etc.