Re: A practical and compelling distributed cap platform: Sandstorm on Cap'n Proto

Kenton Varda <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAJaLmO5BXsx4Y97p+pg5Xamt8wuSOivswuum7Hm-mDogvMz2aQ@mail.gmail.com>
On Tue, Aug 5, 2014 at 11:59 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote:

> Hmm, why not go for a layered defence? The TCB for ocap language runtimes
> is still uncomfortably large IMO.
>

If we were running one app per VM (possibly multiple instances of the app,
but all of the same app), then the worst case is that the app can break
confinement and collude with other instances of itself -- something that
essentially all apps we use today can already do, so it can't be *that*
bad. ;) In order to attack some other app, it would also have to break out
of the VM, so that's two layers.

That said, I was mostly idly speculating here. I don't expect to abandon
Linux containers in the foreseeable future.

-Kenton

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.