12 ms·
Microsoft open-sources LiteBox, a security-focused library OS
- aktau 8mo agoFrom the GitHub page: LiteBox is a sandboxing library OS that drastically cuts down the interface to the host, thereby reducing attack surface. It focuses on easy interop of various "North" shims and "South" platforms. LiteBox is designed for usage in both kernel and non-kernel scenarios. LiteBox exposes a Rust-y nix/rustix-inspired "North" interface when it is provided a Platform interface at its "South". These interfaces allow for a wide variety of use-cases, easily allowing for connection between any of the North--South pairs. Example use cases include: - Running unmodified Linux programs on Windows - Sandboxing Linux applications on Linux - Run programs on top of SEV SNP - Running OP-TEE programs on Linux - Running on LVBS
- aktau 8mo agoMore links with discussion: Reddit discussion: https://www.reddit.com/r/linux/comments/1qw4r71/microsofts_new_opensource_project_litebox_as_a https://www.reddit.com/r/linux/comments/1qw4r71/microsofts_n... Project lead James Morris announcing it on social.kernel.org: https://social.kernel.org/notice/B2xBkzWsBX0NerohSC https://social.kernel.org/notice/B2xBkzWsBX0NerohSC
- deleted 8mo ago[deleted]
- xjamesmorris 8mo agoFYI, I am not the project lead for Litebox. It is led by Microsoft Research.
- aktau 8mo agoSorry about that, I can no longer edit my comment. Do you have any relation with the project apart from working at the same company?
- a-dub 8mo agois this wslv1.2 (wslv1 redux) in now a more general cross-platform library firewall type thing?
- rbanffy 8mo ago> - Running unmodified Linux programs on Windows This might actually be my favourite use: I always thought WSL2 was a kludge, and WSL1 to be somewhat the fulfilment of the "personality modules" promise of Windows NT.
- dixie_land 8mo agoYup WSL feels closer to the Services for Unix which has been around since NT 4/5. It was sad to see WSL2 taking the path of least resistance, that decision has always felt TPM driven ("we got unexpected success with WSL and people are asking for more, deliver xxx by Q4! No I don't care _how_ you do it!")
- unixhero 8mo agoPersonality was an OS aphorism that went longer back than NT I believe. But my memory is fuzzy on this. Edit! Memory unfuzzed: It was Workplace OS, https://en.wikipedia.org/wiki/Workplace_OS https://en.wikipedia.org/wiki/Workplace_OS
- rbanffy 8mo agoI know that, but Windows NT actually succeeded.
- oofbey 8mo agoThe amount of techno jargon marketing speak in this readme is impressive. I’m pretty well versed in most things computers, but it took me a long time to figure out what the heck this thing is good for. Leave it to Microsoft to try to rename lots of existing ideas and try to claim they’ve invented something amazing when it’s IMHO not all that useful.
- alvinunreal 8mo ago[flagged]
- gloflo 8mo agoDont spam.
- usefulposter 8mo agoStop spamming. https://news.ycombinator.com/item?id=45077654 https://news.ycombinator.com/item?id=45077654 - "Generated comments and bots have never been allowed on HN"
- kvuj 8mo agoThe cargo.lock file is 2200+ lines long. Did they spend a reasonable amount of time auditing these dependencies?
- Andrex 8mo agoThey ran it through Copilot which gave it the all-clear.
- TheSilva 8mo ago[flagged]
- RoyTyrell 8mo agoNope, that's a very fair poke at MS. They've gone so far into AI adoption that it's become absurd. - They have VPs posting on Linkedin about rewriting existing code using AI and adhering to arbitrary metrics of a x% rewrite and laying off y% of engineers that used to work on it. - Renaming one of their major flagship product lines (MS Office) to (MS Copilot Apps 365). - Forcing AI features on users despite not wanting it, and overriding OS configuration that should turn it off. - Executives publicly shaming the general public for not wanting "all the AI all the time".
- shikon7 8mo agoWhat would be a reasonable amount of time to audit the dependencies?
- kvuj 8mo agoI would let them decide based on their security policy. If Microsoft states that they don't have any for a project like this, I would be wary of taking it too seriously.
- adolph 8mo agogrep 'name = ' ms-litebox-Cargo.lock | wc -l 238 edit: grep 'name = ' ms-litebox-Cargo.lock | sort -u | wc -l 221
- anon291 8mo agoA library os to me would typically mean it's aimed at hosting a single user program on bare hardware. I don't see that here, but maybe I'm just confused
- richardlblair 8mo agoThe reddit conversation seems to allude to you being correct.
- bri3d 8mo agoIt's both; it's aimed at hosting a single user program on another userspace, but also seems to have its own kernel as well? The "North" part seems to be what I think you'd traditionally think of as a library OS, and then the "South" part seems to be shims to use various userlands and TEEs as the host (rather than the bare hardware in your example). I'm really confused by the complete lack of documentation and examples, though. I think the "runners" are the closest thing there is.
- ukuina 8mo agoNo deployment instructions?
- PunchyHamster 8mo ago[flagged]
- RoyTyrell 8mo agoJust assume the only thing a human did was name write the initial prompt.
- portly 8mo agoI read this type of (sour) comment more and more on this forum. To me it reads very cynical and I wonder what the author is trying to say with this. Are you perhaps negatively impacted by automatic coding?
- blibble 8mo agowe are ALL negatively impacted by generative excrement I have to use Windows at my day job and my god, I'd prefer Windows 3.1
- RoyTyrell 8mo agoNope, not at all. I read your comment as ignorant to AI's capabilities and their negative outcomes with relying on vibe coding. The implication is that MS is forcing AI adoption on users at a point of absurd recklessness, and that they should not be trusted - especially not blindly trusted. Perhaps the reason you're seeing comments similar to my original comment more frequently is because actual software engineers whom know the capabilities of AI and how much of a bad decision it is to assume it's as good as a competent engineer. Many engineers have had years of experience working with management, whom while have legit concerns about the capabilities of software as they are ultimately responsible for it and the financials, see them turning to vibe coding and relying on it. Non technical folks think software is kinda easy to do, and because LLMs can generate code that it just proves their assumptions.
- blackqueeriroh 8mo agoCan you define “non-technical folks” for me? Because last I checked there are a LOT of “technical” people who aren’t software engineers, and a lot of “non-technical” people who don’t believe software is “kinda easy to do.” It’s really frustrating to see comments like this with absolutely zero sourcing, but just stated as fact. It’s giving “I saw ads on LinkedIn and it made me anxious about a world where I can’t make six figures being in control of what tools people have access to”
- CasualSuperman 8mo agoWith how buggy their flagship OS has become, why would I trust anything else they release to be better? Or even if it does work well now, why should I expect it to stay that way? Microsoft has burned through all possible goodwill at this point, at least for me.
- rafram 8mo agoThis isn't supposed to replace Windows, and it isn't a GUI desktop operating system at all. I doubt anyone working on this has anything to do with the modern Windows desktop UX.
- dspillett 8mo ago> This isn't supposed to replace Windows, OP wasn't suggesting it was, just that the lack of quality in one significant area of the company's output leads to a lack of confidence in other products that they release.
- viraptor 8mo agoGiven anything the size of Microsoft, it's not a good assumption. MS has large research teams that produce really interesting things. Their output is unrelated to released products.
- dspillett 8mo agoCompanies want us to trust their things based on positive experiences with their other things, and that works both ways.
- Reddit_MLP2 8mo agobut if the host OS is already comprised, what is the point of sandbox inside of it?
- necovek 8mo ago
- sscarduzio 8mo agoCan it replace Wine to run Windows apps on Linux?
- marklar423 8mo agoIIUC, if you have the source you can recompile said Windows app with LiteBox to statically link in the Windows OS kernel dependencies, so it'll run on any compatible processor regardless of OS (since it won't be making syscalls anymore). It's a unikernel basically. That's the theory, but I don't know how far LiteBox is along to supporting that workflow.
- johannes1234321 8mo agoThey say > It focuses on easy interop of various "North" shims and "South" platforms. For replacing wine on Linux the "North" would be kernel32 API or similar, the "South" would be Linux sys all API. However this is meant as a library, thus require linking the Windows program to it and eine is more than the system interface, it has all the GUI parts etc of win32 API
- cbondurant 8mo agoat first I thought library OS might have meant an OS meant for use at a library. Honestly far less interesting to know I was wrong.
- KPGv2 8mo agoyeah, same here, I was like "wow what an interesting side to their business, a whole operating system intended to serve public and academic libraries!"
- rendaw 8mo agoIs it not? You link the "library os" and you no longer need an os (when running in a supervisor) IIUC.
- stackghost 8mo agoI think parent poster was referring to an actual library, i.e. where you would borrow books. That's also what I thought this was, and came to the comments expecting to see something neat about why libraries might need bespoke operating systems.
- rendaw 8mo agoAh right! Yeah, I did think that too..., like locked down so random patrons couldn't do this or that. I was thinking that was quite a pivot for MS though too...
- noumenon1111 8mo agoMe too. Honestly I was vibing on nostalgia for this: https://en.wikipedia.org/wiki/Dynix_(software) https://en.wikipedia.org/wiki/Dynix_(software)
- loufe 8mo agoThe lack of integrated sandboxing in windows compared to android/iphone is still frankly unacceptable. I've become increasingly paranoid about running any application on Windows (not that your average linux distro is even remotely better) and yet Apple and Google seem to be far, far ahead in user permissions (especially with GrapheneOS, god bless that team) and isolation of processes. Consumers and businesses deserve better. It's crazy to me that in 2026 Notepad++ being compromised means as much potential damage as it does, still.
- digiown 8mo agoThe sandboxing on mobile platforms puts the OS vendor in a special position to enforce a monopoly on apps and features. Apple enforces it aggressively, while Google only reluctantly so far. It also prevents the user from exerting full control of the system. Apple does it by locking things down directly, while Google punishes you for owning your devices with attestation. There has to be a better way. I think Linux's flatpak is a reasonable approach here, although the execution might be rather poor. I want a basic set of trusted tool that I can do anything with, and run less trusted tools like GUI programs in sandboxes with limited filesystem access.
- wat10000 8mo agoThose are policy decisions not really connected to the sandboxing technology. They control what sort of signing the system will accept and make it so that it only runs things they approve, and they only approve things that are sandboxed a certain way. The exact same sandboxing could be used with a system where an admin user can decide what gets to run and what kind of sandboxing is required for each thing.
- pjmlp 8mo agoUWP, and MSIX on Win32 via Appstore. There is also sandboxing configuration via Intune for enterprises.
- malkia 8mo agoThere are containers, and one of their users is the Windows Sandbox - https://learn.microsoft.com/en-us/windows/security/application-security/application-isolation/windows-sandbox/ https://learn.microsoft.com/en-us/windows/security/applicati...
- hypfer 8mo ago"We did not find any viable commercial use for it, but maybe you will."
- gdevenyi 8mo agoWhat is a 'library OS'?
- zamadatix 8mo agohttps://en.wikipedia.org/wiki/Operating_system#Library https://en.wikipedia.org/wiki/Operating_system#Library
- charles_f 8mo agoI think that's an OS in the form of a library, like Wine for example. From what I get from the description it allows you to run programs on your real OS and make it see a cut down API to your actual system to reduce the attack surface.
- bri3d 8mo agoIt's a library that is linked to in place of an operating system - so whatever interface the OS provided (syscalls+ioctls, SMC methods, etc.) ends up linked / compiled into the application directly, and the "external interface" of the application becomes something different. This is how most unikernels work; the "OS" is linked directly into the application's address space and the "external interface" becomes either hardware access or hypercalls. Wine is also arguably a form of "library OS," for example (although it goes deeper than the most strict definition by also re-implementing a lot of the userland libraries). So for example with this project, you could take a Linux application's codebase, recompile it linked to LiteBox, and run it on SEV-SNP. Or take an OP-TEE TA, link it to LiteBox, and run it on Linux. The notable thing here is that it tries to cut the interface in the middle down to an intermediate representation that's supposed to be sandbox-able - ie, instead of auditing and limiting hundreds of POSIX syscalls like you might with a traditional kernel capabilities system, you're supposed to be able to control access to just a few primitives that they're condensed down to in the middle.
- kccqzy 8mo ago> So for example with this project, you could take a Linux application's codebase, recompile it linked to LiteBox If you have to recompile, you might as well choose to recompile to WASM+WASI. The sandboxing story here is excellent due to its web origins. I thought the point of LiteBox is that recompilation isn’t needed.
- tombert 8mo agoI’m not sure I understand what a library OS is; can someone here elaborate?
- greatgib 8mo agoMy understanding of this is that it is a sandbox. Providing a common interface like if it was an OS for the program to run inside, but avoiding the program to use the OS directly. What is unclear is if it uses its own common ABI or if you use the one of the host os. I don't know why but from the project description I have a little bit of feeling that this is another vibe coded project.
- wrs 8mo agoA library OS is an OS that is linked directly to your program instead of being a separate program accessed through a syscall to kernel mode. About the same as a “unikernel”, but a more recent term. Basically it lets your program run directly on a hypervisor VM, though this one will also run as a Linux/Windows/BSD process.
- burnermore 8mo agoBaaah! Microsoft, security-focused in a single sentence!
- bendover690 8mo ago[flagged]
- throwoutway 8mo agoNo mention of starting with a design specification & then tied to formal verification the whole way? It sounds interesting and a step forward (never heard of library Os itll now), but why won't this run into hundreds of the same security bugs that plague Windows if it's not spec'd and verified?
- anon291 8mo agoPeople seem to believe writing things in rust means it's correct.
- R_Spaghetti 8mo agoI'm not sure whether Microsoft, the makers of Windows 95 (after which I stopped taking them seriously), are the sharpest tool in the box when it comes to security.
- deleted 8mo ago[deleted]
- ementally 8mo agoCopilot https://github.com/microsoft/litebox/blob/main/.github/copilot-instructions.md https://github.com/microsoft/litebox/blob/main/.github/copil...
- pjmlp 8mo agoTo be expected, given how many organisations now require employees to use AI if they want to meet their OKRs, especially all that sell AI tools.
- andai 8mo ago[flagged]
- UqWBcuFx6NV4r 8mo ago[flagged]
- llama052 8mo agoBoth can be true.
- outofpaper 8mo agoWhat's dumb, on top of everything, is needing to store non special standard operating procedures in specific AI folders and files when wanting to work with AI tooling.
- WorldMaker 8mo agoCopilot today supports the top-level AGENTS.md approach as well, which seems to be the cross-tool "standard".
- int_19h 8mo agoIt is a standard in a sense that they will all read it (although last I checked you still need to adjust the default config with Gemini). But feature support varies between different tooling. For example, only Claude supports @including other files.
- deleted 8mo ago[deleted]
- ho_schi 8mo agoAnother layer (ouch) to abstract away Windows (ouch * ouch). Use Linux or BSD and ignore that approach for Vendor Lock-in* into their “library OS”.
- 5o1ecist 8mo ago[flagged]
- 5o1ecist 8mo ago[flagged]
- pizzanfurniture 8mo ago[dead]
- runjake 8mo agoFor others as lost as I am and want the tl;dr: A library OS is an operating system design where traditional OS services are provided as application-linked libraries, rather than a single, shared kernel serving all the programs.
- cmrdporcupine 8mo agoI know we're not supposed to complain about comment quality, but -- I came here to look for interesting technical analysis but instead it's Slashdot level snipes about Microsoft the company. And yes, I also dislike Windows and Microsoft generally but this looks like a very interesting project and I'm frankly frustrated at the level of discussion here, it's juvenile. This has nothing to do with Windows, and it looks like most people didn't even read past the title. I'll play with this later today after work and see how mature it is and hopefully have something concrete and constructive to say. Hopefully others will, too.
- BrouteMinou 8mo agoI am with you on that. HN is becoming a "14 years old edgy mini-tech" Facebook. "Microsoft bad, Linux good" kind of comments are all over the place. There is no more in depth discussions about projects anymore. Add the people linking their blogs only to sell you thier services for an imaginary problem, and you get HN 2026. It's maybe the time to find another tech media. If you know one, I would be glad to know.
- MatejKafka 8mo agoLobste.rs mostly are what HN used to be, with less focus on startup culture and more focus on hacking.
- bigstrat2003 8mo agoAnd with idiotic blocking of people based solely on the browser they use. They are small minded people over at lobster.rs.
- bg24 8mo agoWould be nice to see an OCI runtime and if it can give high-performant I/O as opposed to other we have today (eg. Gvisor).
- mlacks 8mo ago[flagged]
- HendrikHensen 8mo agoThanks, ChatGPT.
- salvesefu 8mo agoThe GPT found this and thought it was relevant: "an introduction of library operating system for Linux" - https://lwn.net/Articles/637658/ https://lwn.net/Articles/637658/
- sneak 8mo agoIt runs linux programs, not PowerPoint or Excel.
- dzonga 8mo agoMicrosoft gonna release a windows flavored Linux Distro soon ;)
- Brian_K_White 8mo agoAliens come to visit. I have to tell one the difference between an app linked against a "library os" running on a hypervisor, and an app running on a kernel. I couldn't do it with a straight face.
- perbu 8mo agoA proper library OS doesn't have syscalls. Everything operates in the same space, no user/kernel split.
- palata 8mo agoFirst time I hear the concept of "library OS". Is it similar to e.g. gVisor? Like would gVisor count as a library OS, too?
- zx8080 8mo agoMicrosoft? No, thank you.
- hulitu 8mo agoSeeing Microsoft and security-focused in the same semtence makes me suspicious.
- tnodir 8mo agoIt'll be interesting if MS allows to write e.g. WFP callout drivers via LiteBox and not requiring attestation signing. It'll still work in kernel mode, unlike NetworkExtensions in MacOS.