4 ms·
Software sandboxing has a relatively good cost-to-benefit ratio at reducing the consequences of software bugs, which is why it's already implemented in a lot of
by dhx 2y ago
Software sandboxing has a relatively good cost-to-benefit ratio at reducing the consequences of software bugs, which is why it's already implemented in a lot of software we all use every day. For example, it exists in Android apps, iOS apps, Flatpak apps (Linux), Firefox[1][2], Chromium browsers[3][4][5], SELinux-enabled distributions such as Fedora and Hardened Gentoo[6], OpenSSH (Linux)[7], postfix's multi-process architecture with use of ACLs, etc.
Kubernetes, Docker and systemd folk will be familiar with the idea of sandboxing for containers too, and they're able to do so using much higher level controls, e.g. turn on Kubernetes "Restricted pod security standard" for much stricter sandboxing defaults. Even if containerisation and daemon sandboxing aren't used, architects will understand the concept of sandboxing by just specifying more servers, each one ideally performing a separate job with the number of external interfaces minimised as much as possible. In all of these situations, the use of more granular controls such as detailed seccomp-bpf filters is most useful to mitigate the risks introduced by (ironically) security agent software that is typically installed alongside a database server daemon, web server daemon, etc within the same container.
Tweaking some Kubernetes, Docker or systemd config is _much_ cheaper and quicker to implement rather than waiting to rewrite software in a safer language such as Rust (a noble end goal). Even if software were rewritten in Rust, you'd _still_ want to implement some form of external sandboxing (e.g. systemd-nspawn applying seccomp-bpf filters based on some basic systemd service configuration) to mitigate supply chain attacks against Rust software which cause the software to perform functions it shouldn't be doing.
[1] Firefox Linux: https://searchfox.org/mozilla-central/source/security/sandbox/linux/SandboxFilter.cpp https://searchfox.org/mozilla-central/source/security/sandbo...
[2] Firefox Windows: https://searchfox.org/mozilla-central/source/security/sandbox/win/src/sandboxbroker/sandboxBroker.cpp https://searchfox.org/mozilla-central/source/security/sandbo...
[3] Chromium multi-platform: https://github.com/chromium/chromium/blob/main/docs/security/process-sandboxes-by-platform.md https://github.com/chromium/chromium/blob/main/docs/security...
[4] Chromium Linux: https://chromium.googlesource.com/chromium/src/+/0e94f26e8/docs/linux_sandboxing.md https://chromium.googlesource.com/chromium/src/+/0e94f26e8/d... (seemingly Linux sandboxing is experiencing significant changes as this document or one similar to it does not appear to exist anymore)
[5] Chromium Windows: https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md https://chromium.googlesource.com/chromium/src/+/HEAD/docs/d...
[6] https://gitweb.gentoo.org/proj/hardened-refpolicy.git/tree/policy/modules/services/ssh.if https://gitweb.gentoo.org/proj/hardened-refpolicy.git/tree/p...
[7] https://github.com/openssh/openssh-portable/blob/master/sandbox-seccomp-filter.c https://github.com/openssh/openssh-portable/blob/master/sand...