This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...
This is about the implementation in the SerenityOS but it's my favourite explanation so far: https://awesomekling.github.io/pledge-and-unveil-in-Serenity...
Things like Windows Defender and Snap and the recent macOS hardening efforts are patchwork solutions to try and cope with the modern world, but they'll never really be enough because these systems can't be fundamentally re-thought; they have to keep doing everything everybody already expects them to do. Only brand new OSes really get the chance to do things right, and only the mobile ones really had the opportunity to gain wide adoption.
As a Linux-based programmer who hasn't quite delved into the UNIX internals world, knowing that I have to write my own BPF filter or do some crazy stuff with file descriptors (in the case of capsicum) is enough to scare me. But on OpenBSD, I added `pledge` and `unveil` calls to all my silly Python chat bots in 15 mintes
For example, phishing sites would be radically less effective if passwords are not a thing, and everyone logged in using hardware keys (e.g. Yubikeys) which cryptographically prevent phishing.
Of which there have been plenty.