Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".
Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.
rvz · · focus · HN ↗
Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.
lukehandcool · · focus · HN ↗
rvz · · focus · HN ↗
It is perfectly valid to have OSes that are more memory safe by default, and are also open source at the same time.