Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gee, I had kinda hoped/expected that was the case already. Aren't iOS apps sandboxed like that? Sadly, I think many exploits involve chaining until you get to a defect in the kernel -- from which a cgroup namespace wouldn't help much.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: