Re: A practical and compelling distributed cap platform: Sandstorm on Cap'n Proto
Bill Frantz <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <r422Ps-1075i-C6723BA5CB3E4DBEB388FF1FF4A8E0B3@Williams-MacBook-Pro.local> |
On 8/5/14 at 2:50 AM, [email protected] (Kenton Varda) wrote: >In the long run, I hope that people will start writing Sandstorm apps in an >object-capability language, at which point the need for Linux containers >for sandboxing goes away and multiple users can even be served from the >same process, making things even more efficient. At that point it may make >a lot of sense to further transition to running more directly on top of >Nymote, getting rid of the legacy Linux kernel entirely. From the point of view of theoretical isolation, this is correct. From the point of view of assurance, getting the compiler and runtime out of the security kernel is a valuable simplification of that kernel. Bring back the language level isolation to have multiple layers of security, each of which must be breached to have a penetration. Cheers - Bill ----------------------------------------------------------------------- Bill Frantz | Privacy is dead, get over | Periwinkle (408)356-8506 | it. | 16345 Englewood Ave www.pwpconsult.com | - Scott McNealy | Los Gatos, CA 95032