logoalt Hacker News

tfrancisltoday at 3:53 PM2 repliesview on HN

Why are we acting like isolating software is impossible on Linux? It isnt even difficult, there are about a dozen different models to choose from.


Replies

qltetoday at 5:56 PM

AOSP security model relies on an extremely restrictive SELinux config out-of-the-box (that importantly also doesn't impede normal phone/app usage), with the kernel hardened about as much as any cutting edge Linux distro could offer from upstream, plus features that haven't been upstreamed yet (and again, completely transparently to the user).

show 1 reply
Gander5739today at 4:29 PM

It's not impossible, no, but it's not the default, and the different models tend to have various different issues.

show 1 reply