logoalt Hacker News

rvz • today at 6:09 AM • 2 replies • view on HN

Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.


Replies

lukehandcool • today at 6:33 AM

Are you suggesting proprietary software is safer than open source?

➕ show 3 replies
Gigachad • today at 6:12 AM

I think we have moved on from considering Linux secure which is why all of these microVM projects are popping up. Yes you are still exposed to bugs in the hypervisor but that’s a massively smaller attack surface than the entire Linux kernel.