Comment on Safely exposing services to the Internet

<- View Parent
hirihit640@sh.itjust.works ⁨1⁩ ⁨week⁩ ago

Nobody believes virtualization is perfect, it’s just the best we got because:

And anyways, even a separate physical computer can be hacked. If it has networking, there could be a vulnerability in the networking stack. Just making an outbound tcp connection can be enough to be pwned.

I think the closest thing we have to an “invincible” system is seL4, but I rarely hear about amybody using them

original
Sort:hotnewtop