Skip to content

Comment on eBPF Verification Is Untenable

Comments

to secure linux, both ebpf and io_ring need to be disabled in kconfig at kernel compile time.

in security insensitive scenarios, they are both interesting tech.

Radically different thread models. io_uring is conventionally exposed to unprivileged programs, and eBPF virtually never is.

isn’t the current linux security mindset that all access is potentially privileged?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.