‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. snvzz · · focus · HN ↗
    As a reminder: Millions of LoCs that run in supervisor mode. This is what Linux is.

    It is not possible to fix all the bugs. This is simply not doable.

    The solution has to be fundamental.

    The microkernel multiserver system architecture, with a formally verified microkernel. Nothing else can guarantee enforcement of anything.

    In practice, this is the same as saying seL4[0], because there are no alternatives.

    Related: The seL4 summit 2026 vids are finally up[1].

    0. <a href="https:&#x2F;&#x2F;sel4.systems&#x2F;" rel="nofollow">https:&#x2F;&#x2F;sel4.systems&#x2F;

    1. <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;playlist?list=PLd7rrADYxxQQ" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;playlist?list=PLd7rrADYxxQQ

    1. trollbridge · · focus · HN ↗
      History has proven that the microkernels are not necessarily more secure and have their own unique set of problems (see: macOS).
      1. hn_submit · · focus · HN ↗
        MacOS is not a microkernel, but a hybrid. It&#x27;s therefore neither secure nor fast.
        1. trollbridge · · focus · HN ↗
          This is how microkernels generally go: a No True Scotsman once I try to find any real world microkernels you can actually run things on.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.