On Thu, 2017-02-02 at 19:32 +0200, Francisco Barbee wrote: > > So your advice for now would be to use grsecurity > kernel and forget all those jails and namespaces > until someone figure out proper security solution? No, the advice is to learn what you are trying to defend against, instead of wasting time on exploring the zoo of sandboxing apps... There is nothing wrong with -ARCH kernel. Cheers, -- Leonid Isaev