Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eyberg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
Multiple Security Issues in Rust-sudo-rs
(bugs.launchpad.net)
45 points
by
eyberg
11mo ago
|
11 comments
32.
▲
Runc container breakouts: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881
(openwall.com)
4 points
by
eyberg
11mo ago
|
0 comments
33.
▲
by
eyberg
1y ago
Prisma is actually not running that kernel and many of these other workloads are also not running that kernel. Trivial to spin up a prisma postgres instance and see everything from busybox to a full blown proc including very specific linu
34.
▲
by
eyberg
1y ago
We (NanoVMs) can run (both unikernel and normal linux) virtualized workloads on plain old ec2 instances (eg: t2.small).
35.
▲
Re: CVE-2023-51767: a bogus CVE in OpenSSH
(openwall.com)
3 points
by
eyberg
1y ago
|
0 comments
36.
▲
by
eyberg
1y ago
There are a few ways to approach this. If you don't mind owning the orchestration layer this is precisely what firecracker does. If you don't even want to pay for that though scheduling unikernels on something like ec2 gets you yo
37.
▲
by
eyberg
1y ago
I would kinda disagree with this. The whole 'better than nothing' is what gave a huge chunk of people a false sense of security wrt containers to begin with. The reality is that there is no singular create_container(2). Much of th
38.
▲
by
eyberg
1y ago
Bubblewrap has refused to fix known security issues in its codebase and shouldn't be used.
39.
▲
by
eyberg
1y ago
Containers should not be used as a security mechanism.
40.
▲
Unikernel Cronjobs on AWS
(nanovms.com)
2 points
by
eyberg
1y ago
|
0 comments
41.
▲
by
eyberg
1y ago
This is kind of a stupid "benchmark" but if we're going to walk down this road: linux: elapsed: 0.019895s nanos (running on said linux): elapsed: 0.000886s
42.
▲
by
eyberg
1y ago
Packages exist: https://repo.ops.city Mounts also exist - in fact you can hotplug volumes on the fly on all the major clouds. People really like this cause they can do things like rotate ssl certs every few hours. The file syst
43.
▲
ECScape: Understanding IAM Privilege Boundaries in Amazon ECS
(sweet.security)
23 points
by
eyberg
1y ago
|
9 comments
44.
▲
by
eyberg
1y ago
I'm not sure what your comment means? What infrastructure? I just broke apart each of those into examples of how people use them today.
45.
▲
by
eyberg
1y ago
Access Control: There is none internally. We don't have the notion of users. Logging: Keep using whatever you want be it elasticsearch, syslog, cloudwatch, etc. No opinions here. Debugging: GDB works fine and in many cases since you ca
46.
▲
by
eyberg
1y ago
You can also run the full JVM and in fact I'd imagine that's how most of our JVM users actually use it today.
47.
▲
by
eyberg
1y ago
Sorry - just now seeing this. This is a build of PVM that works with Nanos. We're also maintaining that patch set as I don't ever see it getting included into the kernel (not anytime soon anyways).
48.
▲
by
eyberg
1y ago
It doesn't necessarily mean that but yes you most definitely can run native images - another example showing that: https://github.com/nanovms/ops-examples/tree/master/java/07-... . Both of thes
49.
▲
by
eyberg
1y ago
The rabbit hole goes even deeper. Georgios was thinking about this with Jikes even earlier: https://gousios.org/pub/gousios-mscthesis.pdf
50.
▲
by
eyberg
1y ago
https://github.com/nanovms/ops-examples/tree/master/java/04-...
51.
▲
Plague: A Newly Discovered Pam-Based Backdoor for Linux
(nextron-systems.com)
10 points
by
eyberg
1y ago
|
1 comments
52.
▲
Introduction to Unikernel: Building, deploying lightweight, secure applications
(tallysolutions.com)
42 points
by
eyberg
1y ago
|
20 comments
53.
▲
by
eyberg
1y ago
microvms as espoused by things like firecracker offer full machines but have tradeoffs like no gpu (which makes it boot faster) hyperlight shaves way more off - (eg: no access to various devices that you'd find via qemu or firecracker)
54.
▲
by
eyberg
1y ago
No it wasn't - you can still easily replicate. I just did. My point is that you shouldn't go around talking about how "secure" you are when you have large gaping things like this. This btw is not the only major security
55.
▲
by
eyberg
1y ago
These people definitely do not understand security at all: https://github.com/unikraft/unikraft/issues/414 Also - one needs to be careful cause many of the workloads they advertise on their site do not actual
56.
▲
by
eyberg
1y ago
CGI has a very long history of security issues stemming primarily from input validation or the lack thereof.
57.
▲
by
eyberg
1y ago
Outside of nostalgia there's no engineering reason to do this - definitely not for performance. That same go program can easily go over 10k reqs/sec without having to spawn a process for each incoming request. CGI is insanely slow
58.
▲
Vulnerability Advisory: Sudo Chroot Elevation of Privilege
(stratascale.com)
23 points
by
eyberg
1y ago
|
0 comments
59.
▲
by
eyberg
1y ago
> should be foolproof by design. I think this is a core reason why containers have such a horrible security track record. They weren't made by design. One of the large problems is that there is no "create_container(2)". Th
60.
▲
by
eyberg
1y ago
(I'm w/NanoVMs). Firecracker is a complementary technology and not competitive. Our main software - https://nanos.org is a linux kernel guest replacement whereas firecracker is a VMM (host) replacement for something li
More ›