Live data from Hacker News

Microsoft open-sources LiteBox, a security-focused library OS

github.com

201–210 of 239 posts

Re: Microsoft open-sources LiteBox, a security-focused library OS

#201
post #63
post #44

Earlier quoted context omitted.

It's a library that is linked to in place of an operating system - so whatever interface the OS provided (syscalls+ioctls, SMC methods, etc.) ends up linked / compiled into the application directly, and the "external interface" of the application becomes something different. This is how most unikernels work; the "OS" is linked directly into the application's address space and the "external interface" becomes either h…

> So for example with this project, you could take a Linux application's codebase, recompile it linked to LiteBox If you have to recompile, you might as well choose to recompile to WASM+WASI. The sandboxing story here is excellent due to its web origins. I thought the point of LiteBox is that recompilation isn’t needed.

It's absolutely trivial to make a very strict sandbox - just a simple, mathematical Turing machine is 100% safe.

The hard part is having actual capabilities, and only WASI (which is much smaller than WASM) helps here, and it's not clear why would it be any better than other options, like LiteBox. Especially that wasm does have a small, but real overhead.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#202
post #103
post #66

Earlier quoted context omitted.

Looking more closely, it looks like there are some "North" sides (platforms) with ABI shims (currently Linux and OP-TEE), but others (Windows, for example), would still require recompilation. > If you have to recompile, you might as well choose to recompile to WASM+WASI. I disagree here; this ignores the entire swath of functionality that an OS or runtime provides? Like, as just as an example, I can't "just recompile…

I had previous experience with WASM on TEE. Just use the foreign function interface. Remember WASM isn’t native code so you still need other native code to run WASM (such as wasmtime), and you can import other native functions into WASM through the runtime.

Native functions that are no longer sandboxed, defeating the whole purpose.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#203
post #160

Earlier quoted context omitted.

The response appears to be pointing out that with so many employees (engineers), it's unlikely that they all work on Windows.

Don’t the best of the best typically work on OS fundamentals though?

Yes, but the OS fundamentals are for Azure first, Windows last.

Azure makes money, 50% of Windows computers are basically free and need to get you to sign up for a subscription some how. The other 50% are Windows Pro/Enterprise, but MS assumes they'll get that money forever so doesn't put any resources into that. In 10 years the kids switching to Linux on desktop today will be in charge of the business deals and switch corporations to linux because they're not scared of it like the current business IT leaders

Re: Microsoft open-sources LiteBox, a security-focused library OS

#204
post #90

With how buggy their flagship OS has become, why would I trust anything else they release to be better? Or even if it does work well now, why should I expect it to stay that way? Microsoft has burned through all possible goodwill at this point, at least for me.

Microsoft employ over 100,000 engineers. I'd advise against assuming that everything produced by any of them is bad because of bugs in Windows.

I spent 15 years as a senior dev on the Visual Studio team followed by 5 years on the Xcode team at Apple.

Individual engineers can be talented, professional, and end-user focused. Most of that effort gets lost when PMs refuse to work with each other in a coherent manner. Most of the major issues we ran into weren’t engineering bugs per se, they were the result of management refusing to allow teams to communicate effectively.

When we were first building out the original C# functionality, the C# team refused to talk to the existing compiler teams. I spent more time acting as a go-between than I did solving actual technical problems.

Good people can produce crappy software in that environment.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#205
post #203
post #160

Earlier quoted context omitted.

Don’t the best of the best typically work on OS fundamentals though?

Yes, but the OS fundamentals are for Azure first, Windows last. Azure makes money, 50% of Windows computers are basically free and need to get you to sign up for a subscription some how. The other 50% are Windows Pro/Enterprise, but MS assumes they'll get that money forever so doesn't put any resources into that. In 10 years the kids switching to Linux on desktop today will be in charge of the business deals and swit…

They are not free. OEM costs money. Hence with every laptop with Windows preinstalled, you pay a fraction to Microsoft, even if you immediately uninstall and add Linux.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#206
post #2

From the GitHub page: LiteBox is a sandboxing library OS that drastically cuts down the interface to the host, thereby reducing attack surface. It focuses on easy interop of various "North" shims and "South" platforms. LiteBox is designed for usage in both kernel and non-kernel scenarios. LiteBox exposes a Rust-y nix/rustix-inspired "North" interface when it is provided a Platform interface at its "South". These inte…

> - Running unmodified Linux programs on Windows

This might actually be my favourite use: I always thought WSL2 was a kludge, and WSL1 to be somewhat the fulfilment of the "personality modules" promise of Windows NT.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#208
post #2

From the GitHub page: LiteBox is a sandboxing library OS that drastically cuts down the interface to the host, thereby reducing attack surface. It focuses on easy interop of various "North" shims and "South" platforms. LiteBox is designed for usage in both kernel and non-kernel scenarios. LiteBox exposes a Rust-y nix/rustix-inspired "North" interface when it is provided a Platform interface at its "South". These inte…

> - Running unmodified Linux programs on Windows This might actually be my favourite use: I always thought WSL2 was a kludge, and WSL1 to be somewhat the fulfilment of the "personality modules" promise of Windows NT.

Yup WSL feels closer to the Services for Unix which has been around since NT 4/5.

It was sad to see WSL2 taking the path of least resistance, that decision has always felt TPM driven ("we got unexpected success with WSL and people are asking for more, deliver xxx by Q4! No I don't care _how_ you do it!")

Re: Microsoft open-sources LiteBox, a security-focused library OS

#209
post #2

From the GitHub page: LiteBox is a sandboxing library OS that drastically cuts down the interface to the host, thereby reducing attack surface. It focuses on easy interop of various "North" shims and "South" platforms. LiteBox is designed for usage in both kernel and non-kernel scenarios. LiteBox exposes a Rust-y nix/rustix-inspired "North" interface when it is provided a Platform interface at its "South". These inte…

The amount of techno jargon marketing speak in this readme is impressive. I’m pretty well versed in most things computers, but it took me a long time to figure out what the heck this thing is good for. Leave it to Microsoft to try to rename lots of existing ideas and try to claim they’ve invented something amazing when it’s IMHO not all that useful.

Re: Microsoft open-sources LiteBox, a security-focused library OS

#210

Earlier quoted context omitted.

> People who join ICE to brutalize minorities and protestors are just trying to feed their families too, then. 1400 ISIS (the islamist state) terrorists who made their way to the US, identified by the DHS. https://www.dhs.gov/wow Look at the list here. 2084 pages already, 12 entries per page: that's 25 000 criminals. They're listing their crimes. 25 000 criminals already arrested is a huge lot. Be honest with yoursel…

You are missing out the entire point. In a justice system, a single innocent in prison is a thousand times worse than a free criminal. This is where most people draw the line if they think about it. Because when you put innocents under arrest, suddenly you are no better than dictatorships and terrorist state. The real justice is investing in a security system that tracks, investigates, and condemn actual criminals, i…

[deleted]
Post reply on HN