Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My thoughts exactly. I recently posted the link to that talk here on HN somewhere, and now seeing this is really creepy. Especially:

>All kernel components, device drivers and user applications execute in a single address space and unrestricted kernel mode (CPU ring 0). Protection and isolation are provided by software. Kernel uses builtin V8 engine to compile JavaScript into trusted native code. This guarantees only safe JavaScript code is actually executable.

>Every program runs in it's own sandboxed context and uses limited set of resources.



How's that creepy?

It's freakin awesome!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: