Interests: News, Finance, Computer, Science, Tech, and Living

  • 3 Posts
  • 35 Comments
Joined 2 years ago
cake
Cake day: June 13th, 2023

help-circle


  • Android is Linux using SELinux for user confinement plus users do not have root access and it uses verified boot to enforce all that.

    Keep in mind the system meaning root can do anything it wants. User apps cannot though they can ask the system to do certain things for example by SUID executables for example or other methods. Not sure how android actually does it.

    What is different about Android is owner, user, work profiles, and the new private space structure. Not sure low level how that is done but presumably combination of different users, SELinix, and different encryption keys.





  • flatbield@beehaw.orgtoLinux@lemmy.mlAlternatives to VirtualBox?
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    4 days ago

    Virtualbox should not run slowly in terms of compute. Make sure your allocating enough cores and memory, and VT/AMD-V is enabled in the BIOS of the host. Also Guest additions should be installed. Not sure but that might help IO speeds.

    What might be slow, Graphics may not be acceralerated. Exactly what VM software to use, what it works with, and actually getting it to work can be challanging. Installing guest drivers though is probably required.

    For Linux KVM solutions are probably preferred and more native solution but more technical to use. Getting graphics acceleration with KVM has been challenging, though may be possible. KVM is used widely on servers, but is not that desktop friendly.

    All VM solutions are resource intensive. Use containers and/or native software to reduce/avoid that.

    Edit: I myself have used VirtualBox but these days I use KVM including on my workstation.


  • flatbield@beehaw.orgtoLinux@lemmy.mlLinux is fucking awesome
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    4 days ago

    At work the only issue I ever found is the requirement to use Power Point for presentations and Word for filing patents. LibreOffice just did not translate well enough. Have not tried OnlyOffice.

    Edit: Complex Excel sheets especially with macros would be a problem too. These are not always cross version Excel compatible for that matter. One reason I shifted that stuff to Python long ago and voided that issue.



  • The system is complex plus a lot of legacy history. APTs for example (Advanced Persistent Threats). I think I have heard, that you can no longer guarantee that wiping the system and reinstalling the OS will eliminate them in all cases. They could for example burrow into the Firmware and Microcode.

    Or look at Windows, MS has had huge problem with old drivers and other stuff they run at very high permission levels. Windows is full of stuff from 25 years ago when security did not matter.











  • I was more thinking of the CGI script vunerability that showed up a few years ago. In that case data came from the web into the shell environment uncontrolled. So uncontrolled data processing where the input data crosses security boundaries is an issue kind of like a lot of the SQL injection attacks.

    Another issue with the shell is that all proccesses on the system typically see all command line arguments. This includes any commands the shell script runs. So never specify things like keys or PII etc as command line arguments.

    Then there is the general robustness issue. Shell scripts easy to write to run in a known environment and known inputs. Difficult to make general. So for fixed environment and known and controlled inputs that do not cross security boundaries probaby fine. Not that, probablay a big issue.

    By the way, I love bash and shell scripts.