LWN.net Logo

Qubes beta 1 released

Qubes beta 1 released

Posted Apr 14, 2011 8:05 UTC (Thu) by renox (subscriber, #23785)
In reply to: Qubes beta 1 released by alvieboy
Parent article: Qubes beta 1 released

> Applications already run in an isolated context (meaning they cannot interfere with each other, except on some specific scenarios, like SHM).

Isolated? Not so much, you forget about the filesystem, X, etc.
And the number of vulnerability reports existing show that this isolation do fail.

> As long as system calls are properly protected,[cut]

Note that Chrome developers complained of the difficulty of protecting system calls on Linux (lack of standardised sandbox), so apparently it's not easy..


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds