Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".
Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.
I think we have moved on from considering Linux secure which is why all of these microVM projects are popping up. Yes you are still exposed to bugs in the hypervisor but that’s a massively smaller attack surface than the entire Linux kernel.
Are you suggesting proprietary software is safer than open source?
Not sure what licensing has to do with software engineering or system design.
I’m sure there are proprietary systems with fewer memory safety vulnerabilities than Linux (and many others with more).
It's got nothing to do with the licensing, but it used to be 'with enough eyes all bugs are shallow' for code developed in the open.
Now, open code allows anyone with tokens to burn to analyze it for hidden weaknesses. That makes publishing code a risky move unless you've already invested a lot of effort in securing it.
> 'with enough eyes all bugs are shallow'
This was always nonsense. It assumes that the eyes know what they're looking at. Most people don't know how to look at code and see attack paths.
It is actually becoming true that we have enough eyes (machine attention), though even when the bugs were shallow, normal users didn't look for them.
I think the current state of bug bounties demonstrates that it's about the eyes, not the number.
Agents seem to be* getting better at decompiling; if that appearance is true, binaries are vulnerable in a similar way to source code.
* I don't know how useful any of the specific benchmarks on this are, so I'm only saying "seem to be"
Very frequently when troubleshooting things with an agent it goes off, grabs a compiled library or executable from the system, decompiles it and figures out the exact bug, a possible solution, and if there are workarounds I can apply before upstream fixes it.
Agents are quite capable of using Binary Ninja and Ghidra if they are hinted with a reverse engineering skill.
You can't analyze binaries you don't have access to. E.g. code that lives on an application server and is only accessible via an API.
True, but a separate axis to open/closed source.
GrapheneOS is open source and more secure than stock Pixels and MacOS is closed source and more secure than traditional desktop Linux. Open source does not make software more secure by itself and neither does making it closed source.
You said that.
It is perfectly valid to have OSes that are more memory safe by default, and are also open source at the same time.