http://forums.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/t/walled-garden-firewall-whitelisting-application-whitelisting-sudo-lockdown-superuser-mode-protected-mode/5725/14
Quote Solar Designer (someone that Joanna Rutkowska respects):
Ideally, there should be no SUID binaries reachable from the user account, as otherwise significant extra attack surface inside the VM is exposed (dynamic linker, libc startup, portions of Linux kernel including ELF loader, etc.)
No idea yet.
Related: walled garden, firewall whitelisting, application whitelisting, sudo loc… 1 Like show post in topic Home Categories Guidelines Terms of Service Privacy Policy Powered by...