| ▲ | Razengan 3 hours ago | ||||||||||||||||
Also, operating systems should let us set filesystem permissions per app/process/executable instead of just user accounts. Similar to how macOS/iOS Sandboxing works but at a more lower and granular level | |||||||||||||||||
| ▲ | Retr0id 3 hours ago | parent | next [-] | ||||||||||||||||
SELinux is basically this. | |||||||||||||||||
| |||||||||||||||||
| ▲ | strbean 2 hours ago | parent | prev | next [-] | ||||||||||||||||
https://www.canyonroad.ai/ does some of this in a way tailored to agents. | |||||||||||||||||
| ▲ | pianopatrick an hour ago | parent | prev | next [-] | ||||||||||||||||
personally I wish the OS would allow syscall filtering per user | |||||||||||||||||
| ▲ | Jhater 3 hours ago | parent | prev [-] | ||||||||||||||||
[dead] | |||||||||||||||||