| ▲ | ijustlovemath 3 hours ago | |||||||||||||||||||||||||
I've found it interesting that systemd and Linux user permissions/groups never come into the sandboxing discussions. They're both quite robust, offer a good deal of customization in concert,and by their nature, are fairly low cost. | ||||||||||||||||||||||||||
| ▲ | nextaccountic 2 hours ago | parent | next [-] | |||||||||||||||||||||||||
Unix permissions were written at a time where the (multi user) system was protecting itself from the user. Every program ran at the same privileges of the user, because it wasn't a security consideration that maybe the program doesn't do what the user thinks it does. That's why in the list of classic Unix tools there is nothing to sandbox programs or anything like that, it was a non issue And today this is.. not sufficient. What we require today is to run software protected from each other. For quite some time I tried to use Unix permissions for this (one user per application I run), but it's totally unworkable. You need a capabilities model, not an user permission model Anyway I already linked this elsewhere in this thread but in this comment it's a better fit https://xkcd.com/1200/ | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| ▲ | vbezhenar 2 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||
Linux kernel is ridden with local privilege escalation vulnerabilities. This approach works for trusted software that you just want to contain, but it won't work for malicious software. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| ▲ | moezd 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||
This assumes people know more than just writing Dockerfiles and push straight to production. This is still a rarity. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||
| ▲ | pjmlp 3 hours ago | parent | prev | next [-] | |||||||||||||||||||||||||
Because that is actually UNIX user permissions/groups, with a long history of what works, and what doesn't? | ||||||||||||||||||||||||||
| ▲ | hendry an hour ago | parent | prev | next [-] | |||||||||||||||||||||||||
Agreed! systemd nspawn is actually pretty awesome, though not many people use it. | ||||||||||||||||||||||||||
| ▲ | ape4 2 hours ago | parent | prev [-] | |||||||||||||||||||||||||
cgroups are part of whats used to implement docker and podman | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||