Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because you don't want every process to have control over the file system and other processes.

This limits the impact of a misconfigured service, a compromised service, or just a plain malicious service... or users of such services.

Then, it doesn't necessarily have to be malicious, you can also harm your system by accident. I have done it many times.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: