Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not unless your entire stack down to the bare silicon is also FLOSS, and the community is able to verify.

There is a lot of navel gazing in these comments about "the perfect solution", but we all know (or should know) that perfect is the enemy of good enough.



> Not unless your entire stack down to the bare silicon is also FLOSS,

https://news.ycombinator.com/item?id=27897975


We've seen countless examples of relatively minor libraries being exploited which then cause havoc because of a spider web of transitive dependencies.


On Qubes OS (my daily driver), which runs everrything in VMs with strong, hardware virtualization, you can use minimal operating systems with very low number of installed libraries for security-critical actions: https://www.qubes-os.org/doc/templates/minimal/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: