4 ms·
Google hardened the KVM and what is used. So native instruction execution but sandboxed. Then the gnu/Linux applications run in containers. So do not lose th
by jacksmith21006 8y ago
Google hardened the KVM and what is used. So native instruction execution but sandboxed.
Then the gnu/Linux applications run in containers.
So do not lose the secure aspect of Chromebooks but get native gnu/Linux.
- shmerl 8y agoDo you mean it runs a whole OS in the container, or it binds application to the host OS?
- jacksmith21006 8y agoGoogle has created a hardened KVM that it is using. So the GNU/Linux instruction run native on the processor but just sandboxed from the Linux kernel used by ChromeOS. Then they use containers between the GNU/Linux applications. This is different than how they did Android. Android is done using the same kernel as ChromeOS and using containers. But it is locked so can be secure. Google implementation of GNU/Linux is going to be far more secure. But all of this is hidden from the user. From the UI standpoint the user has no idea what is happening under the covers. You install a GNU/Linux application and it is added to the app drawer like an Android app or anything else.
- diffeomorphism 8y ago> Google hardened the KVM and what is used. So native instruction execution but sandboxed. That makes no sense. KVM is used for virtualization, e.g. I use it to run windows VMs. So not native and not a sandboxed container but a VM? Or is the KVM part wrong and it actually uses containers like crouton?