Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hayali
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
Syd Domain Transitions
(man.exherbo.org)
2 points
by
hayali
3mo ago
|
0 comments
2.
▲
Syd sandbox has new Tutorial
(man.exherbo.org)
3 points
by
hayali
6mo ago
|
0 comments
3.
▲
Syd: Writing an application kernel in Rust [video]
(fosdem.org)
19 points
by
hayali
7mo ago
|
0 comments
4.
▲
Medicine for Gpg.fail
(crates.io)
2 points
by
hayali
9mo ago
|
1 comments
5.
▲
by
hayali
9mo ago
Port of OpenBSD's signify to Rust.
6.
▲
Syd-TUI: Syd's Terminal User Interface
(asciinema.org)
1 points
by
hayali
11mo ago
|
1 comments
7.
▲
by
hayali
11mo ago
cargo install syd-tui
8.
▲
BalCCon2k25: Syd, an Advanced Introduction to Secure Application Sandboxing [video]
(youtube.com)
2 points
by
hayali
11mo ago
|
0 comments
9.
▲
by
hayali
1y ago
This seems to be mostly useless ai hype. Firstly it's quite impolite to assume all open sources projects are hosted on github/gitlab. That said, I uploaded sydbox.git temporarily to gitlab to have it scanned. It took 10 minutes to
10.
▲
RFC: FSF40 Hackaton Idea: Opening Untrusted Documents with Emacs+Syd
(lists.libreplanet.org)
1 points
by
hayali
1y ago
|
1 comments
11.
▲
by
hayali
1y ago
Emacs turns into Dangerzone! syd'em all! syd'em no regrets!
12.
▲
by
hayali
1y ago
Updated sydbox to 3.35.0: hardened Landlock, empty mount namespaces using pivot_root and root:tmpfs a la bubblewrap, many bug fixes thx to LTP, many bug/portability fixes thx to Alpine Linux folks. New utilities syd-fd and syd-x. See t
13.
▲
Syd+Youki=Syd-OCI: Introduction to a Secure Container Runtime for Linux [video]
(fosdem.org)
2 points
by
hayali
1y ago
|
1 comments
14.
▲
by
hayali
1y ago
Scroll down a bit for the video that was just uploaded.
15.
▲
by
hayali
2y ago
Here is a snapshot from the first ever server in the observable universe running Hardened Exherbo, https://0x0.st/8Z3h.png , which displays a very interesting and afaik novel usecase of notify action. if you read seccomp-uno
16.
▲
by
hayali
2y ago
better go for the latest version syd-3.32.0 which I've released shortly after fosdem. This release (hopefully) finishes the sandbox categorization work, check out https://man.exherbolinux.org/syd.7.html#SANDBOXING if y
17.
▲
Syd: An Introduction to Secure Application Sandboxing for Linux [video]
(fosdem.org)
37 points
by
hayali
2y ago
|
4 comments
18.
▲
by
hayali
2y ago
In this talk, I will introduce Syd, a GPL-3 licensed, rock-solid application kernel designed for sandboxing applications on Linux systems (version 5.19 and above). Over the past 16 years, Syd has evolved from a tool used within Exherbo Linu
19.
▲
Syd-3.24.4: Reduces overhead to 15%-17%, meanwhile Gvisor is at 40%-80%
(lists.sr.ht)
2 points
by
hayali
2y ago
|
0 comments
20.
▲
Sydbox is now faster than GVisor: A funny optimization story
(lists.sr.ht)
5 points
by
hayali
2y ago
|
2 comments
21.
▲
by
hayali
2y ago
Nipped in the bud? Back to the roots!
22.
▲
by
hayali
2y ago
Finally, you're recommending this to be in the kernel. I agree for the most part, however this should be as an extra layer. The more layers, the merrier! One known example is Dirty CoW which don't work under Syd or GVisor. Also th
23.
▲
by
hayali
2y ago
Also note, Syd has been used as Exherbo's default sandbox for 16 years now and Exherbo is a source-based distribution which enables package testing by default (we call them "build_options: recommended_tests"), and every packa
24.
▲
by
hayali
2y ago
slight correction, it's "pandora profile -mtrace/allow_unsafe_memory:1 firefox", as firefox by default uses JIT which needs WX memory.
25.
▲
by
hayali
2y ago
Thank you for your kind words. As the author of syd and an Exherbo developer, I am working on a sibling distro called "Hardened Exherbo": https://hexsys.org . The idea is to contain all service daemons with Syd. I don&#
26.
▲
by
hayali
2y ago
This one almost made me laugh. Syd is a _unikernel_ and as such much simpler in design than GVisor which is a full-blown user-space kernel.
27.
▲
by
hayali
2y ago
Imho, you're judging syd too harshly without really understanding it: > for example, silently turning O_RDWR into O_WRONLY This is only done for Crypt sandboxing and admittedly it's mostly aimed for encrypting small files that
28.
▲
Syd the perhaps most sophisticated sandbox for Linux
(rentry.co)
55 points
by
hayali
2y ago
|
19 comments
29.
▲
SydBox Mitigates SROP
(man.exherbolinux.org)
3 points
by
hayali
2y ago
|
0 comments
30.
▲
SydBox starts enforcing PIE by default
(man.exherbolinux.org)
2 points
by
hayali
2y ago
|
0 comments
More ›