Post #2314275
2026-05-08 06:43 UTC
Both CopyFail and DirtyFrag (and the ones that will surely come after) are demonstrating the value of using microVMs to isolate untrusted workloads.
Replies (1)
-
@penguin42@mastodon.org.uk 2026-05-08 11:42
@slp@fosstodon.org Yeh - a lot of people were always very sold on namespace containers being secure somehow; by magic I guess. I guess seccomp also is curious here - these algorithm interfaces and similar ar ethe rare things you'd want to filter off but are hard.