Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
daymanstep
4 months ago
|
parent
|
context
|
favorite
| on:
The foundations of a provably secure operating sys...
Doesn't that mean that your process is then responsible for ensuring that an app with a read-only capability cannot do a write ?
You're moving the burden of enforcement from the kernel to the user level ?
josephg
4 months ago
[–]
Yes, microkernels like SeL4 do almost all real work out of the kernel, and in userland processes. It’s much more secure that way.
Consider applying for YC's Winter 2027 batch!
Applications
are open till November 2.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
You're moving the burden of enforcement from the kernel to the user level ?