HN Hall of Fame Weekly email

Firejail: Light, featureful and zero-dependency security sandbox for Linux

firejail.wordpress.com Software & code Software projects Security & privacy Candidate
Screenshot of firejail.wordpress.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 5 calendar years, with breakout response in 2 of them.

submissions
6
submitters
6
observed span
2016–2023
peak thread · 59 comments
159 pts
latest 20+ return · 2023-07-11
159 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

See also Bubblewrap[1]. I use Bubblewrap all the time, because it's just useful, and a bit easier than doing things with unshare directly. To compare and contrast: bubblewrap is lower level, and is great for embedding or using in one-off invocations, whereas firejail is more oriented towards adding a bit of hardening to everyday applications like Firefox via built-in and custom profiles. For example, you could temporarily override a path doing something like this: bwrap --bind / / --bind /tmp/myoverride…

jchw·159-point thread·

Just a reminder that seccomp is available to all the applications, and if you include it in the app itself, you can limit the privileges much better than firejail can. For example apps don't usually need to read config, or don't need to open new listening sockets once their initialised. This can be easily done in the app, but not by firejail. I'm quite disappointed projects don't integrate that functionality upstream. The only popular one I know of is chrome.

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
2

100+ points or 50+ comments

Total points
296

reference only — not used in Hall rules or ranking

Total comments
91

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2016-08-06Firejail – security sandboxFirst breakoutsimonpure12832
2018-05-16Firejail – Linux namespaces and seccomp-bpf sandboxworez30
2018-07-06Firejail can sandbox any type of processespatternexon20
2019-08-28Firejail – easy sandbox for any program on Linuxausjke30
2020-05-21Firejail: Increase security by restricting applications' running environmentjmngomes10
2023-07-11Firejail: Light, featureful and zero-dependency security sandbox for LinuxBest thread · Latest 20+ point returnnateb202215959