Re: A practical and compelling distributed cap platform: Sandstorm on Cap'n Proto
Kenton Varda <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAJaLmO5BXsx4Y97p+pg5Xamt8wuSOivswuum7Hm-mDogvMz2aQ@mail.gmail.com> |
On Tue, Aug 5, 2014 at 11:59 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote: > Hmm, why not go for a layered defence? The TCB for ocap language runtimes > is still uncomfortably large IMO. > If we were running one app per VM (possibly multiple instances of the app, but all of the same app), then the worst case is that the app can break confinement and collude with other instances of itself -- something that essentially all apps we use today can already do, so it can't be *that* bad. ;) In order to attack some other app, it would also have to break out of the VM, so that's two layers. That said, I was mostly idly speculating here. I don't expect to abandon Linux containers in the foreseeable future. -Kenton _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk