Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> You're not secure until you whitelist.

No, a whitelist isn't good enough. You can't anticipate an exhaustive list of the programs the user will want to run.

What you can do, however, is enforce a policy by which programs are required to provide machine-checkable evidence, also known as proof-carrying code [https://en.wikipedia.org/wiki/Proof-carrying_code], that they respect the system's safety policy.

> it's a necessary but sufficient condition

Perhaps you mean “not sufficient”?



Yes, that's what I meant -- not sufficient.

Whitelisting seems to be working out well for Apple. It's a big part of why they're the most secure smartphone platform.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: