Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ignoring all the warts of how schizophrenic the different AWS layers are, I personally like the policy document format.

I wouldn’t mind a similar style at the OS/kernel level for control groups and other permissions of that type. Having a list of principals and allowed operations would be easier to reason about (imho) than systemd unit files, or selinux, or filesystem permissions, or firewall rules, or the rest of the mess which is Linux security.

I think Fuchsia is doing something exactly like that?



Unix groups are much, much easier to correctly configure than everything you mentioned, and at least an order of magnitude simpler as well.


To be fair selinux is a bar so low you'd have to dig to do worse.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: