@spendergrsec@srslypascal@ace__pace Does that mean that io_uring will be turned back on in a future version of @grsecurity? Would unpriv userns be okay if it didn’t grant CAP_NET_ADMIN?
Why would the government have an obligation to search for and save the life of a billionaire who willingly took a submarine to the ocean floor but not a kid with cancer who can’t afford healthcare?
@RnaudBertrand Imagine if the USA closed all their overseas bases, cut military spending by 90%, and tried to actually compete with China by building infrastructure, educating citizens and growing their own economy.
Radical concept, I know.
@SwiftOnSecurity The correct solution is an _on-premises_ reverse proxy connected to the device via a physical cable (no switches!). Preferably with the reverse proxy server’s own listening endpoint bound to a VPN interface.
@SwiftOnSecurity Sorry, but Azure AD Application Proxy is _not_ the correct tool for this, because the connection from the cloud to the on-premises management interface is still unprotected.
To the best of my knowledge, formal verification (preferably with the proofs made publicly available) is the only way to stop the stream of easy software-only attacks.
The point is that being certified to e.g. EAL5+ and AVA_VAN.5 has turned out to not actually mean very much. Devices meant to guard against state-level actors have repeatedly fallen to much weaker attackers.
@IronbugVR @javierdavalos@Apple@unity@FigminXR If I am correct, Apple isn’t forbidding passthrough because they want to, but rather because allowing passthrough would violate their security model.
@javierdavalos@Apple@unity@FigminXR That leaves only one other option, and that is to ensure that untrusted apps cannot access sensitive data at all. This results in a declarative API, which is exactly what Apple implemented.
@javierdavalos@Apple@unity@FigminXR I’m not sure if confinement (preventing a process from exfiltrating data) is even possible on Apple’s GPUs, and even if it was, the overhead would almost certainly be prohibitive.