Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I like having to install the things I really want, which gives me a chance to consider the security implications of them, instead of having many things pre-installed and I don't know what the total risks are. And nothing else I know of has gone since ~1996 with only 2 of the worst kind of security holes (i.e., remote exploit of something I didn't even need, but was installed by default).

In the base install are many useful things (including a web server IIRC, though the port is not exposed by default), and those are audited and have that excellent track record.

Then when you install extra things, they are usually limited by what user they run as, and usually have pledge/unveil run (limiting access to predetermined/approved syscalls and parts of the file system) so they can't break other things if compromised.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: