5 ms·
The cloud environment where the code runs might be ephemeral, but it would most likely have access to some not so ephemeral resources that should still be prote
by mxey 5y ago
The cloud environment where the code runs might be ephemeral, but it would most likely have access to some not so ephemeral resources that should still be protected.
If one wants to go sandboxing, the right place for it would be in npm, where packages should not be able to modify anything but themselves.
- ghuntley 5y agoDon’t think within a package manager is the right place. Fundamentally there needs to be an onion layer around the entire activity (ie. a virtual machine, qubeos, oci/container, gitpod, github codespaces, namespace jail). Example of tasty file that a package manager should never be able to read: /Users/mxey/.ssh/ssh_rsa or /Users/mxey/.netrc
- Ginden 5y agossh_rsa shouldn't be readable to browser, Spotify, Zoom or whatever is currently running. And browser files should be isolated from any other process etc. Linux security model (and I suppose other OSes too, but I'm most familiar with) is fundamentally incompatible with desktop environments. Mobile OSes got it much better. I love Snap because it confines processes to sandbox.
- kevinmgranger 5y agoLinux _does_ have SELinux. It's just too confusing to use.
- Ginden 5y agoIt's unusable for anyone but few highly qualified sysadmins. If good security isn't easily obtainable for tech-savvy person in one hour, there is basically no security.
- mxey 5y agoIt has to be on the level of the package manager, if you want to avoid package A interfering with package B
- thingification 5y agoFundamentally according to what theory? https://medium.com/agoric/pola-would-have-prevented-the-event-stream-incident-45653ecbda99 https://medium.com/agoric/pola-would-have-prevented-the-even...