| ▲ | black_knight 2 hours ago | |||||||||||||
I think we could get a lot further if we implement proper capability based security. Meaning that the authority to perform actions follows the objects around. I think that is how we get powerful tools and freedom, but still address the security issues and actually achieve the principle of least privilege. For FreeBSD there is capsicum, but it seems a bit inflexible to me. Would love to see more experiments on Linux and the BSDs for this. | ||||||||||||||
| ▲ | Findecanor 14 minutes ago | parent | next [-] | |||||||||||||
Redox is also moving towards having capabilities mapped to fd's, somewhat like Capsicum. Their recent presentation at FOSDEM: https://fosdem.org/2026/schedule/event/KSK9RB-capability-bas... | ||||||||||||||
| ▲ | Noumenon72 22 minutes ago | parent | prev | next [-] | |||||||||||||
Seems like a bad time to bring this up when it wouldn't have helped with this attack at all. | ||||||||||||||
| ▲ | h4x0rr 2 hours ago | parent | prev [-] | |||||||||||||
Eli5, what is that supposed to mean? | ||||||||||||||
| ||||||||||||||