Nerd Sniped by BINFMT_MISC
blog.jessfraz.com
Nerd Sniped by BINFMT_MISC
1–10 of 36 posts
Re: Nerd Sniped by BINFMT_MISC
#2...
Re: Nerd Sniped by BINFMT_MISC
#3> Hacker news, you can shove your comments right up your ...
Re: Nerd Sniped by BINFMT_MISC
#4> Hacker news, you can shove your comments right up your ...
>Imagine if an entire OS had all the languages packaged this way so that everything could be “dot slashed” and executed but without actually installing the language to your host operating system.
This has been technically possible for decades, but the disadvantages (startup time, memory use, disk use) outweigh the advantages. (better security, assuming no VM escape bugs, which is an assumption you absolutely can't make, considering the long list of Xen CVEs) Breezily asserting the superiority of this solution without acknowledging any possible downsides is also strange... more press release than blog post.
Re: Nerd Sniped by BINFMT_MISC
#5> Hacker news, you can shove your comments right up your ...
Yes, very odd. Don't think I'll be upvoting this submission. >Imagine if an entire OS had all the languages packaged this way so that everything could be “dot slashed” and executed but without actually installing the language to your host operating system. This has been technically possible for decades, but the disadvantages (startup time, memory use, disk use) outweigh the advantages. (better security, assuming no V…
Also, this is a write-up about something cool that author discovered. It’s about the fact that dot slash isn’t magic, but rather a feature which can be (ab)used to do something out of the ordinary. Sounds like a blog post to me.
Re: Nerd Sniped by BINFMT_MISC
#6Earlier quoted context omitted.
Yes, very odd. Don't think I'll be upvoting this submission. >Imagine if an entire OS had all the languages packaged this way so that everything could be “dot slashed” and executed but without actually installing the language to your host operating system. This has been technically possible for decades, but the disadvantages (startup time, memory use, disk use) outweigh the advantages. (better security, assuming no V…
Containers aren’t VMs. There’s no VM to escape, and Xen has nothing whatsoever to do with containers. Ironically, there’s a really good explanation of this topic which was given by the author at a conference. Also, this is a write-up about something cool that author discovered. It’s about the fact that dot slash isn’t magic, but rather a feature which can be (ab)used to do something out of the ordinary. Sounds like a…
https://nvd.nist.gov/vuln/search/results?adv_search=false&fo...
https://nvd.nist.gov/vuln/search/results?adv_search=false&fo...
Re: Nerd Sniped by BINFMT_MISC
#7Re: Nerd Sniped by BINFMT_MISC
#8Re: Nerd Sniped by BINFMT_MISC
#9> Hacker news, you can shove your comments right up your ...
Re: Nerd Sniped by BINFMT_MISC
#10Earlier quoted context omitted.
Containers aren’t VMs. There’s no VM to escape, and Xen has nothing whatsoever to do with containers. Ironically, there’s a really good explanation of this topic which was given by the author at a conference. Also, this is a write-up about something cool that author discovered. It’s about the fact that dot slash isn’t magic, but rather a feature which can be (ab)used to do something out of the ordinary. Sounds like a…
An excellent and helpful correction. But security-wise chroot/runc is even worse than Xen, since the attack surface is so much bigger! https://nvd.nist.gov/vuln/search/results?adv_search=false&fo... https://nvd.nist.gov/vuln/search/results?adv_search=false&fo...