bug#43770: Geeks think securely: VM per Package (trustless state to devs and their apps)

2020-10-05 Thread Ludovic Courtès
Hi, bo0od skribis: > Actually what i wanted to say but seems i missed it, This security > design can be engineered and implemented when Guixsd released based on > GNU-Hurd Kernel. Because its going to be totally new kernel and having > this feature is without question the best security feature

bug#43770: Geeks think securely: VM per Package (trustless state to devs and their apps)

2020-10-02 Thread bo0od
Hey, Actually what i wanted to say but seems i missed it, This security design can be engineered and implemented when Guixsd released based on GNU-Hurd Kernel. Because its going to be totally new kernel and having this feature is without question the best security feature for the future of

bug#43770: Geeks think securely: VM per Package (trustless state to devs and their apps)

2020-10-02 Thread raingloom
On Fri, 2 Oct 2020 18:01:18 + bo0od wrote: > Hi There, > > If we look at current state of packages running inside GNU distros > they are in very insecure shape which is either they are installed > without sandboxing because the distro doesnt even provide that or no > profiles exist for the

bug#43770: Geeks think securely: VM per Package (trustless state to devs and their apps)

2020-10-02 Thread Ricardo Wurmus
Hi, this does not look like an actionable bug report. What is it exactly that ought to be done in your opinion? -- Ricardo

bug#43770: Geeks think securely: VM per Package (trustless state to devs and their apps)

2020-10-02 Thread bo0od
Hi There, If we look at current state of packages running inside GNU distros they are in very insecure shape which is either they are installed without sandboxing because the distro doesnt even provide that or no profiles exist for the sandboxing feature and has issues e.g: - Sandboxing can