Nice read on sandboxing with bwrap: sloonz.github.io/posts/sandbo...
Everybody knows that allowing different applications unlimited access to each other’s data is not exactly optimal from a security point of view. While servers have enjoyed containers to isolate applic...