3 ms·
Whilst I like getting more control of my hardware, I really prefer if I can contain arbitrary software - sandbox it and compartmentalise it. If arbitrary proces
by eptcyka 2mo ago
Whilst I like getting more control of my hardware, I really prefer if I can contain arbitrary software - sandbox it and compartmentalise it. If arbitrary processes can own your whole system, is anyone truly an owner?
- rep_lodsb 2mo agoThis requires access to hardware registers, so it won't work as non-root or inside a VM.
- fsflover 2mo agoSo you might like Qubes OS, which isolates all apps into hardware-assisted VMs. You will still have all the access from the AdminVM, but arbitrary processes won't.
- VorpalWay 2mo agoYou probably misunderstood the technical writeup (if you read it). This is modifying MMIO registers of the DRAM controllers. Normal user space (ring 3) doesn't have access to that. Nor does a VM guest. This needs host kernel level access to begin with. And that is the layer that should be in complete control of the system. There shouldn't be a hidden OS underneath that I can't replace.