An Exhaustive Whitepaper and Systems Architecture on Cryptographic Enclaves, Authenticated Boot, Ephemeral Process Scoping, and Threat Modeling across [NixOS][nixos], [nix-darwin][nix-darwin], [nixbsd][nixbsd], [nix-on-droid][nix-on-droid], [home-manager][home-manager], and [hjem][hjem].
The vulnerabilities and architectural design flaws addressed in this whitepaper are not unique to declarative systems; they exist on every modern general-purpose operating system in the world (including Arch Linux, Debian, Ubuntu, Fedora, Alpine, macOS, and FreeBSD):
- The Flat POSIX User Boundary: On every standard POSIX system, any unconfined process running under a user account (
UID 1000) has full kernel permission to inspect any file owned by that user, dump unhardened