Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

CloudABI - Capability Based Security on Linux/Unix

EuroPython Conference via YouTube

Overview

Explore capability-based security on Unix systems with CloudABI in this EuroPython conference talk. Dive into the design principles of CloudABI, a POSIX-based computing environment that enhances security by restricting processes to only affect provided file descriptors. Learn how CloudABI removes APIs capable of acquiring global resources, requiring processes to be granted specific capabilities. Discover the benefits and trade-offs of this approach, including the ability to safely execute unknown binaries without containers or virtual machines. Gain insights into writing Python software for CloudABI, potential pitfalls to avoid, and the current and future status of this technology. Compare CloudABI to traditional Unix security models and understand its implementation across various operating systems, including BSD, Linux, and macOS.

Syllabus

Intro
Background
Problem
CloudABI
API Removal
Capability Tokens
Example Configuration
Future Possibilities
Questions

Taught by

EuroPython Conference

Reviews

Start your review of CloudABI - Capability Based Security on Linux/Unix

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.