Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Same worries and setup here, with the only difference that I use Nix to either spawn a QEMU VM or build an LXC container that runs on a Chromebook (through Crostini).

I started using throwaway environments, one per project. I try keeping the stuff installed in the host OS to the bare minimum.

For the things I need to run on the host, I try to heavily sandbox it (mostly through the opaque macOS sandbox) so that it cannot access the network and can only access a whitelist of directories. Sandboxing is painful and requires trial an error, so I wish there was a better (UX-wise) way to do that.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: