Hacker News new | ask | show | jobs
by n3rv 25 days ago
Letting RIOT into your ring ZERO is not a risk I'm willing to take.

It just sits nagging in the back of your mind. So why take the risk.

1 comments

Are you playing games on a different user? If not a user space program can already access all your files and memory of running processes.
yama? ptrace scope? namespaces? selinux? apparmor?

of course depends also on system defaults, but then why I cannot dump ssh-agent process from same user?

oh maybe that's also the reason why the move to the kernel level in general? or that's not necessary with different privileges and they could stay on user space without taking over kernel? (insert here philosoraptor meme pls)

again having low leve drivers from external corps that could ready anything anytime from my system and exfiltrate without me even knowing is even more scary than running a recent microsoft os! and should be avoided if possible!

Talking about Windows here as we're discussing kernel anti cheat.

>again having low leve drivers from external corps

What do you think drivers are then?

Userspace program at least needs admin privs to read others' memory, right?
That's the thing, they don't for processes of the same user.