3 ms·
What's sad is that processes are already virtual machines, they just need to have a better permissions system. What's really sad is that for the most part those
by jdewerd 3y ago
What's sad is that processes are already virtual machines, they just need to have a better permissions system. What's really sad is that for the most part those better permissions systems have been built (namespaces/cgroups on linux, gatekeeper on Mac OS) but nobody figured out how to expose that to end users before the business people figured out that there were trillions of dollars available if you charged rent to centrally manage it.
We were so close. Sigh.
- lox 3y agoIs this not essentially what docker did with cgroups? It’s incredibly tricky securing containers, I’m not at all confident process only sandboxes would be adequate.
- theossuary 3y agoThere's a big difference between securing containers, and using them to prevent Adobe from polluting they entire system. Containers are an excellent way to provide lower guarantees of security (though still more than is there currently), with higher usability. Microvms also fit into the model very cleanly and could be used transparently when higher security was required. The fact that VMs are necessary has shown how much OSes have failed. That we need to take an OS and package it into multiple VMs to get any real isolation is a problem that OSes should solve for.
- PaulDavisThe1st 3y ago> The fact that VMs are necessary has shown how much OSes have failed. The fact that VMs exist at all shows how much OSes have succeeded.
- xorcist 3y agoDocker makes it really hard to do anything with cgroups. Unless you mean letting Docker manage everything about them, in which case you can configure nothing. Systemd did the cgroups thing right. Apart from the v1/v2 thing, but if you can use only v2 then you do not need to think about it.