‹ BackHN Continuity

Thread

Is sandboxing sufficient to contain rogue agents?

52 points · 99 comments · zdw

  1. rvz · · focus · HN ↗
    Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

    Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.

    1. lukehandcool · · focus · HN ↗
      Are you suggesting proprietary software is safer than open source?
      1. rvz · · focus · HN ↗
        You said that.

        It is perfectly valid to have OSes that are more memory safe by default, and are also open source at the same time.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.