Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nicecars
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
nicecars
2y ago
Safari actually implements Site Isolation. Process-per-tab isolation was introduced in Safari 15 in 2021, and site isolation features were further enhanced in Safari 16.4.
2.
▲
by
nicecars
2y ago
QubesOS lacks Secure Boot implementation and has insufficient boot chain protection. Its security heavily relies on OS isolation through the Xen hypervisor, though it remains vulnerable to attacks on the hypervisor itself. Furthermore, the
3.
▲
by
nicecars
2y ago
I agree. I haven't seen any Linux OS with proper security featuring dm-verity-based Secure Boot (except for documentation in Arch explaining how to implement it). Most distributions cannot be considered security-hardened by default. Wh
4.
▲
by
nicecars
2y ago
Fedora Silverblue's Secure Boot is also primarily for UEFI support and not fundamentally designed to create a boot chain or detect attacks on the OS. Additionally, it has weaknesses in kernel protection mechanisms (insufficient kernel
5.
▲
by
nicecars
2y ago
While Linux systems like ChromeOS and Android could be considered sufficiently hardened, mainstream distributions generally don't prioritize security, with developers simply creating what they prefer. They lack comprehensive security f
6.
▲
Are there any FOSS OS with macOS-level security?
7 points
by
nicecars
2y ago
|
16 comments
7.
▲
What are some less well-known but interesting Linux Security Summit projects?
2 points
by
nicecars
2y ago
|
0 comments
8.
▲
by
nicecars
2y ago
Sorry, I meant greater than 5.
9.
▲
by
nicecars
2y ago
I'm simply curious and would like to play with it if it's there :)
10.
▲
Are there any FOSS operating systems that are certified EAL 5 or higher by CC?
1 points
by
nicecars
2y ago
|
6 comments
11.
▲
by
nicecars
2y ago
Why would be UNIX-like? Is it meant to be a UNIX architecture?
12.
▲
by
nicecars
2y ago
Is full application/process separation due to virtualization or sandboxing? Or by a validated kernel hypervisor? Or something like Unikernel?
13.
▲
by
nicecars
2y ago
Why?
14.
▲
by
nicecars
2y ago
Xen
15.
▲
by
nicecars
2y ago
It's very helpful! Thanks! But is this a single unikernel? Or is it a management of them?
16.
▲
OS for Secure Containers?
7 points
by
nicecars
2y ago
|
6 comments
17.
▲
Huawei's HongMeng(Harmony) kernel appears to be EAL6 certified [pdf]
(commoncriteriaportal.org)
3 points
by
nicecars
2y ago
|
0 comments
18.
▲
by
nicecars
2y ago
Thank you! Now I understand that my threat model is not good! I remembered the NSA criteria, Separation Kernel Protection Profile
19.
▲
by
nicecars
2y ago
structure -> kernel
20.
▲
by
nicecars
2y ago
Is there a structure like the NT kernel(openVMS) (in FOSS) that is more stable and less vulnerable than the NT kernel?
21.
▲
by
nicecars
2y ago
Sorry for the uninformed question. I asked this question out of interest. The most aggressive attacker is because I recall that there used to be a criterion on Wikipedia (I don't remember which page, but I heard it was cancelled when t
22.
▲
by
nicecars
2y ago
So what if it is simply used for browsing (GUI) only? I'm thinking in this case Kiosk or Chrome.
23.
▲
by
nicecars
2y ago
Does running Linux on SEL4 only prevent attacks on the hardware or firmware level if Linux is compromised?
24.
▲
by
nicecars
2y ago
I like it
25.
▲
What is the most secure FOSS operating system with Internet access?
10 points
by
nicecars
2y ago
|
23 comments