Hacker News new | past | comments | ask | show | jobs | submit login

I don't think that helps much. OpenBSD already only allows syscalls originating out of the libc .text section, so whether the trap itself comes from a syscall instruction or some other trap mechanism doesn't really improve security AFAICT.



Yeah but it sounds super cool doesn’t it!


Every time I've seen a dev team go down that road, it's come with rather unfortunate unintended side effects.

https://devblogs.microsoft.com/oldnewthing/20041215-00/?p=37...


Yeah but think of the attacks I thought of in the shower that it mitigates




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: