Hacker News
Software Sandboxing: The Basics
Software sandboxing limits a process’s privileges programmatically without administrative authority, as defined by Julien Tinnes and Chris Evans in 2009. Traditional UNIX tools like setuid and chroot are inadequate for developers, leading to modern interfaces such as FreeBSD Capsicum and Linux Seccomp that extend privilege-dropping capabilities. The article critiques legacy suid-binary approaches and highlights the importance of keeping privileges strictly decreasing to maintain the principle of least privilege.