I agree that it would be great to have a tag for this SIG (#ConfinedUsers).
I started blogging about what I’m working on that is related to that SIG effort:
- sudo without a setuid binary or SSH over a UNIX socket - Siosm’s blog
- Don’t change your login shell, use a modern terminal emulator - Siosm’s blog
I have another one in progress about the security model, suid binaries and NoNewPrivs.