privilege-restriction

2 articles
sort: new top best
clear filter
0 7/10

Comprehensive technical comparison of FreeBSD's Capsicum and Linux's seccomp-bpf sandboxing models, analyzing their opposite architectural philosophies (capability subtraction vs. syscall filtration) and demonstrating why Capsicum's structural approach is immune to bypass vulnerabilities like CVE-2022-30594 that affect filter-based systems.

FreeBSD Linux Capsicum seccomp seccomp-bpf Robert Watson Jonathan Anderson Andrea Arcangeli Will Drewry CVE-2022-30594 USENIX Security tcpdump BPF PTRACE_SEIZE
vivianvoss.net · vermaden · 5 days ago · details · hn
0 5/10

Agent Safehouse is a macOS-native sandboxing tool that enforces kernel-level deny-first access controls to restrict LLM agents (Claude, Codex, Gemini, etc.) to specific project directories, preventing accidental or malicious access to sensitive files like SSH keys and AWS credentials outside the target workspace.

Agent Safehouse Claude Codex Gemini Copilot Cursor Cline Aider eugene1g
agent-safehouse.dev · atombender · 5 days ago · details · hn