|
|
|
|
|
by ignoramous
382 days ago
|
|
> ... drastically restrict the syscall API surface available to the sandboxee, which quickly reduces its value ... Depends I guess as Android has had quite a bit of success with seccomp-bpf & Android-specific flavour of SELinux [0] > Until we have a properly hardened and memory safe OS ... faster than running MicroVMs on a Linux host. Andy Tanenbaum might say, Micro Kernels would do just as well. [0] https://youtu.be/WxbOq8IGEiE |
|