‹ BackHN Continuity

Thread

Is sandboxing sufficient to contain rogue agents?

52 points · 99 comments · zdw

  1. rvz · · focus · HN ↗
    Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

    Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.

    1. lukehandcool · · focus · HN ↗
      Are you suggesting proprietary software is safer than open source?
      1. Cider9986 · · focus · HN ↗
        GrapheneOS is open source and more secure than stock Pixels and MacOS is closed source and more secure than traditional desktop Linux. Open source does not make software more secure by itself and neither does making it closed source.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.