Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well my point is that switching to a commit-based workflow with no runtime changes doesn't solve the problem of adobe setup including a malicious commit.

Isolating things to a specific folder is what actually gives any security here, and you can do that on a writable /etc too.



yes and you need shared read-only global state. like resolv.conf




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: