Conversation
Notices
-
Embed this notice
feld (feld@friedcheese.us)'s status on Tuesday, 04-Mar-2025 14:20:58 JST feld
@varx Yeah you could, and I just remembered I didn't write a blog post to document how I improved security of a docker container with this. That's a worthwhile thing to do if you can -
Embed this notice
varx/tech (varx@infosec.exchange)'s status on Tuesday, 04-Mar-2025 14:20:59 JST varx/tech
I've seen #AppArmor used primarily to *harden* the security of an existing program. Is it also reasonable to use it to *sandbox* known-malicious code? Or are other methods required?
(I assume you also want ulimit or similar on the side, but that's to prevent resource consumption attacks rather than sandbox escapes.)
-
Embed this notice