hn.today

MXC - a sandboxed code execution system

github.com75 points43 comments
Screenshot of MXC - a sandboxed code execution system

Commenters discussed Microsoft’s MXC as a cross-platform sandboxing/runtime for executing untrusted code, with some praising features like a “learning” mode, permissive MIT license, optional telemetry disclosures, and readable docs (dannyw). Others raised desires for dynamic, grant-as-needed permissions and nonblocking dashboards to approve aggregated blocked accesses (neobrain). Several noted MXC’s multi-platform ambition and compared it to Flatpak or other runtimes (smitty1e, hobofan), while contributors described using alternatives like smolvm, OpenShell, Nono, or slopbox for specific needs (LeBit, pprotas). A recurring theme was frustration at multiple projects converging on similar sandbox engines rather than a shared standard, with calls for a minimal common policy model to ease portability and auditability (minraws, rock_artist, lifeisloving).

Others were sharply critical about security, trust, and implementation choices. Kernc and ishKebab questioned provenance and large Rust code counts versus comprehensibility; dannyw rebutted the raw SLOC claim and warned against DIY bash sandboxes, pointing out concrete flaws in a separate project. Rfgplk asserted MXC/bubblewrap had sandbox-escape and capability mistakes, and fg137 doubted Microsoft’s ability to produce a cross-OS solution that meets enterprises’ needs (macOS seatbelt limitations noted). Torginus suggested WebAssembly as an alternative sandboxing approach, while zenapollo rejected the project on brand grounds. Opinion therefore splits between cautious optimism about MXC’s utility and strong concerns about fragmentation, correctness, and security.

Read on github.com43 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.