Live data from Hacker News

Viewing profile — nicecars

nicecars

HN member
Joined
Wed, Aug 21, 2024, 1:34 AM UTC
HN karma
8
Public activity
26 items

About nicecars

No profile information was provided.

Recent public activity

  1. comment
    Comment #42895120

    Safari actually implements Site Isolation. Process-per-tab isolation was introduced in Safari 15 in 2021, and site isolation features were further enhanced in Safari 16.4.

  2. comment
    Comment #42885405

    QubesOS lacks Secure Boot implementation and has insufficient boot chain protection. Its security heavily relies on OS isolation through the Xen hypervisor, though it remains vulne…

  3. comment
    Comment #42885369

    I agree. I haven't seen any Linux OS with proper security featuring dm-verity-based Secure Boot (except for documentation in Arch explaining how to implement it). Most distribution…

  4. comment
    Comment #42885348

    Fedora Silverblue's Secure Boot is also primarily for UEFI support and not fundamentally designed to create a boot chain or detect attacks on the OS. Additionally, it has weaknesse…

  5. comment
    Comment #42885286

    While Linux systems like ChromeOS and Android could be considered sufficiently hardened, mainstream distributions generally don't prioritize security, with developers simply creati…

  6. story
    Are there any FOSS OS with macOS-level security?

    macOS have superior security compared to standard Linux/BSD distributions even at the software level, separate from their hardware lockdown. Are there any FOSS desktop OS with equi…

  7. story
    What are some less well-known but interesting Linux Security Summit projects?

    I would like to know about less well-known but interesting security presented at the Linux Security Summit or other similar events.

  8. comment
    Comment #41535551

    Sorry, I meant greater than 5.

  9. comment
    Comment #41527844

    I'm simply curious and would like to play with it if it's there :)

  10. story
    Are there any FOSS operating systems that are certified EAL 5 or higher by CC?

    Are there any FOSS operating systems that are certified EAL5+ by Common Criteria? I have seen SUSE taking EAL4+ but is it EAL5 or higher?

  11. comment
    Comment #41515793

    Why would be UNIX-like? Is it meant to be a UNIX architecture?

  12. comment
    Comment #41515763

    Is full application/process separation due to virtualization or sandboxing? Or by a validated kernel hypervisor? Or something like Unikernel?

  13. comment
  14. comment
  15. comment
    Comment #41452144

    It's very helpful! Thanks! But is this a single unikernel? Or is it a management of them?

  16. story
    OS for Secure Containers?

    If I need to isolate containers, which is the best OS for containers when security is important: Bottle Rocket, Container Optimized OS or Flatcar and PhotonOS? And why is that? Wha…

  17. comment
  18. story
  19. comment
    Comment #41325426

    Thank you! Now I understand that my threat model is not good! I remembered the NSA criteria, Separation Kernel Protection Profile

  20. comment
    Comment #41316216

    structure -> kernel

  21. comment
    Comment #41315823

    Is there a structure like the NT kernel(openVMS) (in FOSS) that is more stable and less vulnerable than the NT kernel?

  22. comment
    Comment #41315474

    Sorry for the uninformed question. I asked this question out of interest. The most aggressive attacker is because I recall that there used to be a criterion on Wikipedia (I don't r…

  23. comment
    Comment #41315368

    So what if it is simply used for browsing (GUI) only? I'm thinking in this case Kiosk or Chrome.

  24. comment
    Comment #41315357

    Does running Linux on SEL4 only prevent attacks on the hardware or firmware level if Linux is compromised?

  25. comment
    Comment #41315339

    I like it