Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn't see it mentioned, but wouldn't having a RO root filesystem with writable directories mounted noexec also have been sufficient?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: