4 ms·
One based on memory-safe platform/language (think java). Distribution: byte codes, which are get compiled for the actual platform. Encryption by default. Ful
by java-man 2y ago
One based on memory-safe platform/language (think java). Distribution: byte codes, which are get compiled for the actual platform.
Encryption by default. Full separation of applications / processes. Each application sees the permitted sub-space of the file system. No more system-wide and easily corruptible registries or files.
No drive-by installation. No application can get more than permitted.
- r34ct0r14 2y ago[dead]
- nicecars 2y agoIs full application/process separation due to virtualization or sandboxing? Or by a validated kernel hypervisor? Or something like Unikernel?
- java-man 2y agoEvery API (a group of methods) can only be accessible via an interface object (accessor). The application requests an API, gets the accessor, make the call(s). If permission for that accessor was explicitly granted, the calls succeed. Otherwise, the calls never reach the destination. What would you call this arrangement? A supervisor?