4 ms·
Think of the overhead which could be saved if services could be "spun up" in chrooted environments or even just as members of traditional Unix-style user-privat
by MintelIE 6y ago
Think of the overhead which could be saved if services could be "spun up" in chrooted environments or even just as members of traditional Unix-style user-private groups! I know, I know, this is a newish concept which seems crazy. But it could work.
- anthk 6y agoAhem. Chroot has lots of ways to escape.
- MintelIE 6y agoThe article mentions this but links to a Google search as "proof." Even VM's have lots of ways to escape these days. Chroot vulnerabilities have been discovered and fixed over time, as any security issue in an operating system is. It's not accurate to say that they are insecure in a blanket fashion especially these days. My opinion is that we should be using Unix as it is meant to be used, as on operating system, and using its time worn facilities meant for purposes such as security and sandboxing. They are very well tested and the solutions are baked-in and generally pretty small in terms of both code and overhead when compared to spinning up a VM, for instance. There are arguments for using VMs for security and scaling but they don't always win over just one modest local server in either domain. We're not all serving Google search after all.
- lsofzz 6y ago> Chroot vulnerabilities have been discovered and fixed over time, as any security issue in an operating system is. It's not accurate to say that they are insecure in a blanket fashion especially these days. My opinion is that we should be using Unix as it is meant to be used, as on operating system, and using its time worn facilities meant for purposes such as I think you are right in general terms but I do not think an attacker will play by the rule and use `chroot` in UNIX-like OS as it is "meant to be used". They will use whatever means necessary - whether it be 0day or other un-patched vulnerability to get a break out.
- smabie 6y agoDoesn't this apply to really any sort of isolated environment? What's wrong with chroot vs a vm?
- lsofzz 6y ago> Doesn't this apply to really any sort of isolated environment? What's wrong with chroot vs a vm? If you are implying _PoC GTFO_, then definitely I do not have anything to suggest today that either is secure but I would rather not base my comment on what's not seen in the wild and also on the limited breadth of my research. If anything, we've learnt the from past exploitations of guest additions/kernel modules in guests/vmm, that all of it is real and possible. Given enough resource, time and eyeballs, a _lot_ of the bugs are exploitable - you just have to ask some of the folks in offsec who develop exploits for living.