[ cyb / tech / λ / layer ] [ zzz / drg / lit / diy / art ] [ w / rpg / r ] [ q ] [ / ] [ popular / ???? / rules / radio / $$ / news ] [ volafile / uboa / sushi / LainTV / lewd ]

λ - programming

/lam/bda /lam/bda duck
Name
Email
Subject
Comment
File
Password (For file deletion.)

BUY LAINCHAN STICKERS HERE

STREAM » LainTV « STREAM

[Return][Go to bottom]

File: 1449238783144.jpg (973.79 KB, 1629x1113, Girl-in-her-sandbox.jpg) ImgOps Exif iqdb

 No.12482

Let's have a thread about containerization and sandboxing.

I love the idea of compartmentalizing things to increase security. A program that runs in a chroot generally wouldn't be able to see anything outside of its designated area - it's exactly like the matrix.

I'd been using a chroot to run my a web browser with flash player inside for a long time. Recently I've set up an LXC system (linux container) which is supposed to give stronger seperation than a chroot (it isolates more than just the filesystem).

I also use virtualbox for Windows XP (and Dosbox for DOS) - you can do all kinds of things like carefully select which USB devices get through to it, what internet it has. Unlinke a chroot or LXC, you are really running a sepearate OS kernel.

As with anything in security it has two sides: Feel free to discuss chroot breakout attacks, how a lxc container that has X forwarder could key log the host system and so on.
>>

 No.12484

I just read this in a 8/tech/ DNS thread:

>Also, if you're concerned about this, you should be aware that certain programs (like Steam, infamously) will monitor your DNS lookups and send those IP and hostname records to Steam HQ. They issue VAC bans based on IP lookups, if they think you're talking to a hack's DRM server.


I wonder if the bridge networking device that is set up for lxc would block stream from being able to snoop on your DNS requests (the ones happening outside the container)?



Delete Post [ ]
[ cyb / tech / λ / layer ] [ zzz / drg / lit / diy / art ] [ w / rpg / r ] [ q ] [ / ] [ popular / ???? / rules / radio / $$ / news ] [ volafile / uboa / sushi / LainTV / lewd ]