Replying to
@haicen@infosec.exchange @soatok@furry.engineer
This was one of the challenges at NSEC this year.
mastodon 4.7.2+glitchDebian developer, USDS alum. All opinions are my own, &c.
Is the current state of the art for application sandboxing on Linux still bubblewrap, or are there other options out there that aren't at the entire-OS level like Qubes? (I know Spectrum [thanks @qyliss!], but afaik it's still under very heavy development and meant to stand on its own at the OS layer.) #linux #security