The solution involves gVisor, an open-source reimplementation of Linux as a userspace Go application.
It works well enough to run modern browsers and play YouTube at 1080p 60fps without a sweat, and less memory overhead than a full VM.
More to come soon.
@dystopiabreaker@zooko
I will be open-sourcing a project that should massively help with Linux desktop security in the coming weeks.
No, it is not just an AppArmor clone.
Not a KVM frontend either.
But a third, more complex third thing.
Presenting to Qubes devs next week!
the recent signal debate points out something important: desktop OS security is far behind mobile.
there have been incremental developments to improve this situation: QubesOS, OpenBSD's unveil/pledge syscalls, and macOS's incremental development towards something like unveil/pledge
People have the entirely reasonable expectation that desktop operating systems like Windows, MacOS, and Linux should prevent one app from stealing another appโs data. But they donโt. If you want that kind of security, you need to use a mobile phone OS or Chromebook.