When you test an application you have to ask yourself, if the application is trustworthy. After reading
this article about ultra-fast creation of Solaris Container, the following idea came into my mind:
Imagine a wrapper that clones for every application you want to use a container, executes the programm in this containers and destroys the application after the exit of the application. Obviously you would use an shared filesystem for data storage (like /export/home/), but any modification outside the home dir would disappear immediately after executing. Furthermore when the application opens an backdoor and uses an root exploit, the backdoor and the exploit is contained against other users, other applications and other systems.
Or to take it to an extreme: everytime when a users logs into the system a containment container will be created and destroyed. I will think about this idea a little more ...
Comments
Fri, 29.08.2008 13:12
ROTFL
Fri, 29.08.2008 10:37
Unterstützen Seelen Snapshots? Nur so als Sicherheit, falls man vor hat etwas "schlechtes" zu tun...
Thu, 28.08.2008 11:42
I called it fangorn (sindarin for Treebeard) because it´s th e oldest active machine in my home office.
Thu, 28.08.2008 10:23
My old Sun Ultra 10
Thu, 28.08.2008 09:08
Writing this comment on a Sun Ultra6 with 2x450MHz und 2 GB RAM. It is a fine hardware.