Get the latest tech news

FreeBSD Jails Security


I believe this topic is not really well discussed online – and often with multiple misunderstandings. There seems to be this general belief that Podman on Linux is as safe as Jails on FreeBSD…

The idea is simple – you create a directory (or ZFS dataset) that will be your root and extract there FreeBSD Base System like that. Even ‘rootless’ Podman has full access to all Linux kernel syscalls – unless blocked additionally by seccomp command from SELinux solution. Official database of CVE incidents exists and one may just check how many security vulnerabilities were found in a project one is interested.

Get the Android app

Or read this on Hacker News