3 ms·
"Better", but similar, would be to move to OS with the Object Capability model. Applications don't get access-by-default with security bolted on afterward, they
by tech2 10y ago
"Better", but similar, would be to move to OS with the Object Capability model. Applications don't get access-by-default with security bolted on afterward, they get access to the objects they're initially granted and no way whatsoever to access anything beyond that.
Sadly that's a huge change in programming and security model for most and wouldn't be an easy change to make.
- floatboth 10y agoCloudABI https://nuxi.nl/cloudabi/ https://nuxi.nl/cloudabi/ lets you run capability based apps side by side with traditional full POSIX apps on your OS. Out of the box on FreeBSD, patches exist for Linux and NetBSD, userspace support for macOS. So you get one binary that runs on multiple operating systems as a bonus :) The ABI itself is basically "FreeBSD, plus Capsicum always enabled from the start, minus any stuff that doesn't work under Capsicum".
- tech2 10y agoThat's a nice step in the right direction, thanks for bringing it to my attention. It does mean a fair bit of rewriting though which is mostly what my initial comment was trying to get across, it's a different world over there :)