Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Could you expand on the last sentence? Why is relying on chroot+file permissions inherently bad?


chroot has not been designed as a security feature but as a system testing tool. you only need a local root exploit to get out of chroot. you need additional protection to have a proper jail; freebsd does this, openbsd used to, not sure how it is now.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: