Sandbox Your Program Using FreeBSDs Capsicum By Jake Freeland @BsdcanOrg
Sandbox Your Program Using FreeBSDs Capsicum By Jake Freeland  @BsdcanOrg
Uploaded July 2025 | Updated September 2026, 45 minutes ago
With security vulnerabilities rapidly rising each year, program security is more important than ever. One solution to keeping your program from being the victim of the next big CVE is FreeBSD's Capsicum.

Originally developed at the University of Cambridge Computer Laboratory, Capsicum is a lightweight capability and sandbox framework built into the FreeBSD base system. It is designed around the principle of least privilege - where programs only have access to resources that are required for operation.

This talk will follow my blog post, which outlines the process of Capsicumization, or sandboxing your program using Capsicum. I will cover capability violation detection, restructuring existing programs for Capsicum, and filesystem/networking access inside of the capability sandbox.

Recent Capsicumization efforts in the FreeBSD base system and the future of Capsicum will also be discussed.
Sandbox Your Program Using FreeBSDs Capsicum By Jake FreelandHardware-accelerated program tracing on FreeBSD By Bojan NovkovićData Science on FreeeBSDARM64 Maciej CzekajKeynote: Hardware Support for Memory Hungry Applications By Margo SeltzerHeart ticking for a guest running on FreeBSD ARM hypervisor by Mihai CarabasTesting and profiling warm and live migration in bhyve: Elena MihailescuRefining FreeBSDs Kernel Crypto Framework John BaldwinAaron Poffenberger: Fighting Spam at the Frontline   BSDCan 2018Advanced ptrace() usage on FreeBSD By: John BaldwinMaking FreeBSD QUIC By: Tom JonesBSDCan Saturday 2026-06-20: 1120A personal FreeBSD deployment: Dhananjay Balan
BSDCan |

Sandbox Your Program Using FreeBSD's Capsicum By Jake Freeland

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER