Poettering praises FreeBSD Capsicum

I don't agree with Pottering on almost all issues but on the issue that Linux security being a dog's breakfast, I totally agree.
 
Well, Linux has quite a few mitigation mechanisms in the kernel, many more than FreeBSD (without capsicum).

They're not particularly easy to use and they're all optional, so they turn to external sandboxing mechanisms like container runtimes.
 
Back
Top