2 ms·
One of the foundations of object-capability security is memory safety, so loading arbitrary native code does subvert that. You can get around this by, for examp
by nmadden 6y ago
One of the foundations of object-capability security is memory safety, so loading arbitrary native code does subvert that. You can get around this by, for example, requiring native code to be loaded in a separate process. As you say, a capability OS and/or CPU architecture [1] is able to confine native code.
> isn’t it a problem if a module’s permissions may increase without explicit input from the module’s user (transitive or otherwise)?
Exactly right.
[1]: https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/ https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/