logoalt Hacker News

MatejKafkalast Saturday at 2:23 PM4 repliesview on HN

How exactly do you propose to sandbox drivers running in kernel space? Do you even know how drivers work? (I'm guessing no, based on this comment)


Replies

milesvplast Saturday at 3:27 PM

There are people working on this problem honestly. The general solution 10 years ago was a micro kernel. Today, I’m not sure. The linux model is starting to look dated, with similar problems elsewhere. Modern hardware design looks less and less like classic textbook design, with all kinds of random chips having direct memory access to memory the cpu uses on some shared bus. Where even things like on board blue tooth chips can become attack vectors on the system.

There was a good keynote on the topic 5 years ago By Timothy Roscoe

https://www.usenix.org/conference/osdi21/presentation/fri-ke...

show 1 reply
masfuertelast Saturday at 3:12 PM

The User-Mode Driver Framework is a thing. Most plug-in devices do not need (or have) a kernel-mode driver.

show 1 reply
toast0last Saturday at 4:24 PM

Microsoft has a program to do static and dynamic analysis of drivers... not a sandbox, but better than nothing. Of course, wonky drivers plus wonky hardware can still do bad things (io-mmu can help, a bit).

The problems tend to be in the userspace software that's also installed with the driver. Sometimes there's also some pretty derpy stuff where the driver wants to talk to the userspace software but there's no validation/verification and that opens up a big hole.

coldtealast Saturday at 7:13 PM

First of all, drivers don't have to run in kernel space. Do you know that? I'm guessing no, based on your comment.

Second, we're not talking about the drivers per se, as those aren't what shows you ads, it's the configuration software and accompanying crapware. Did you get that? I'm guessing no, based on your comment.

Third, there are capability-based kernels, microkernels, drivers that are allowed into as restricted bytecode, IOMMU, and several other layers of security. Do you know that? I'm guessing no, based on your comment.

show 3 replies