rml, to infosec

Are there any interesting or offensive security reports on cracking or ? I've always been curious what kind of challenges it would present in practice/how much difficulty the immutable store and containerization of packages would really pose, or if there are minor faults throughout the codebase they can easily be tracked down and exploit for professionals. But haven't found any good posts on the matter.

das_g,
@das_g@chaos.social avatar

@rml In normal operation, NixOS doesn't containerize packages. Manipulating $PATH to only have certain software available is good against accidentally using more than one should, but doesn't protect against rouge (or pwned) applications just calling stuff by its fully qualified /nix/store path, so I don't think that'd be much of an obstacle.

An approach (https://grahamc.com/blog/erase-your-darlings/) might grant some protection against intruders persisting a threat, but isn't the default in NixOS.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • mdbf
  • osvaldo12
  • magazineikmin
  • GTA5RPClips
  • rosin
  • thenastyranch
  • Youngstown
  • cubers
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • anitta
  • Durango
  • everett
  • ethstaker
  • cisconetworking
  • Leos
  • provamag3
  • modclub
  • ngwrru68w68
  • tacticalgear
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines