3 ms·
Operating systems could do a way better job in a million ways. 1. There's so little isolation between processes and very little support for saying something li
by staticassertion 5y ago
Operating systems could do a way better job in a million ways.
1. There's so little isolation between processes and very little support for saying something like "I'm a process, please don't fuck with me" - you can only say "I'm a process, don't let me fuck with others". That sucks. There's a bit of work here on Linux with memfd_secret and Windows has a Protected Process thing now that I don't know a ton about.
But basically there's no way as a process to prevent someone injecting into you.
2. Root and Admin are overly powerful as an abstraction. You get root and you're god. The Linux kernel has always treated root -> kernel escalation as a relatively small issue, which means root really is a dangerous thing to provide anyone. Protecting a process from another root process is extremely difficult.
Things are sort of getting better in some ways. Namespaces on Linux are really good - most software should be running in some kind of a namespace since it almost never has any business messing around with global resources like processes, files, etc. With the popularity of Docker things are moving to a bit more of a sane world, but that's more just luck - I don't think people moved to Docker for security but for sanity.
Basically, we went from one global address space to an address space per process, but we left absolutely everything else as global, and this is the result.
- rl3 5y agoThanks, that was informative.