Remix.run Logo
▲ rvz 2 hours ago

Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.

▲lukehandcool 2 hours ago | parent | next [-]

Are you suggesting proprietary software is safer than open source?

▲jasomill an hour ago | parent | next [-]

Not sure what licensing has to do with software engineering or system design.

I’m sure there are proprietary systems with fewer memory safety vulnerabilities than Linux (and many others with more).

▲bzzzt 24 minutes ago | parent [-]

It's got nothing to do with the licensing, but it used to be 'with enough eyes all bugs are shallow' for code developed in the open.

Now, open code allows anyone with tokens to burn to analyze it for hidden weaknesses. That makes publishing code a risky move unless you've already invested a lot of effort in securing it.

▲Cider9986 an hour ago | parent | prev | next [-]

GrapheneOS is open source and more secure than stock Pixels and MacOS is closed source and more secure than traditional desktop Linux. Open source does not make software more secure by itself and neither does making it closed source.

▲rvz 31 minutes ago | parent | prev [-]

You said that.

It is perfectly valid to have OSes that are more memory safe by default, and are also open source at the same time.

▲Gigachad 2 hours ago | parent | prev [-]

I think we have moved on from considering Linux secure which is why all of these microVM projects are popping up. Yes you are still exposed to bugs in the hypervisor but that’s a massively smaller attack surface than the entire Linux kernel.