The embedded long-term support initiative
The embedded long-term support initiative
Posted Oct 30, 2011 17:43 UTC (Sun) by raven667 (subscriber, #5198)In reply to: The embedded long-term support initiative by vonbrand
Parent article: The embedded long-term support initiative
I think we are past that now, the lead kernel developers don't believe or claim that one can successfully run malicious local processes without the possibility of local root compromise. Look at kernel.org where they are no longer giving away shell access just for fun to reduce the attack surface area. No one is making the claim that the linux kernel is sufficiently free of vulnerabilities that one could host multiple malicious users safely on the same system. The talk now is about virtualization for security isolation, what is being done on a single system image isn't good enough.