>> the same exploits. Think of a binary generated elsewhere (where
> "gcc" is available) and put into your environment.

That's pretty bad news :(

> I am convinced that 100 % security is impossible - and correspondingly
> would use a pragmatic approach: I would rely on OS level
> constraints (user with very restricted rights, process running
> in an isolated "box") - and ensure the OS is kept up to date
> to reduce the risk of exploits of OS security weaknesses.

Yes,agree 100% security will never be possible. I'll explore about running
process as an isolated box. Thanks for the suggestions and inputs.

FOSS Programmer.

Reply via email to