Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Doesn't that mean that your process is then responsible for ensuring that an app with a read-only capability cannot do a write ?

You're moving the burden of enforcement from the kernel to the user level ?



Yes, microkernels like SeL4 do almost all real work out of the kernel, and in userland processes. It’s much more secure that way.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: