[svlug] Restricting privileges

Scott DuBois rhcom.linux at gmail.com
Thu Jan 15 11:21:20 PST 2015

On Thu, Jan 15, 2015 at 11:50:21AM +0100, Ivan Sergio Borgonovo wrote:
> There are many software you may use on the internet that may not receive
> the cures they need because they aren't under so heavy scrutiny as
> firefox may be, so make all these stuff running in a container may be
> simpler to maintain than configure apparmor for each of them.

Good point. I've been exposed to containers, and I scratched the surface of
getting involved with OSv, but more important things get in the immediate way.
Taking a look at the LXC site looks interesting as well. Containers are becoming
much more popular these days and I'm still deploying old school full VM's.

Apparmor works great once a person goes through and does their risk assessment
of all apps that would require it and configure as necessary.

EFF ID: 1731778

"The difference between stupidity and genius is that genius has limits."
-- Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 490 bytes
Desc: Digital signature
Url : http://lists.svlug.org/archives/svlug/attachments/20150115/dce8541c/attachment.bin

More information about the svlug mailing list