A blog post exploring software sandboxing fundamentals, discussing the challenges of implementing privilege restriction mechanisms in software without administrative authority. The author shares experiences from work on Emilua, examining traditional UNIX approaches and modern OS interfaces like Capsicum and Seccomp, while cautioning against insecure practices like suid binaries.