Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Don't even need a separate user if you're on linux (or wsl), just use the sandbox feature, you can specify allowed directories for read and/or write.

The sandbox is powered by bubblewrap (used by Flatpaks) so I trust it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: