frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Why isn't capability-based security more common?

3•killerstorm•1h ago
Recent ["self-propagating NPM malware"](https://news.ycombinator.com/item?id=45260741) reminds us that the predominant security model is basically whack-a-mole: you gotta trust _every_ piece of software you run (including all the libraries, plugins, etc), unless you explicitly sandbox it.

Capability-based security might offer an alternative: software should not have access to things when it's not explicitly provided with access. I.e. "classic" desktop security is kind of a blacklist model (everything is possible unless explicitly restricted e.g. via sandbox) while capbility-based security is like a whitelist.

On a programming language level it's usually known as object-capability model, and there's a number of programming languages which implement it: https://en.m.wikipedia.org/wiki/Object-capability_model

The question: why isn't it more popular? It doesn't even seem to be widely known, let alone used. (Aside from isolated examples.)

Is there any chance it would be widely adopted?

I guess one objection is that people don't want to manually configure security. But perhaps it can be integrated into normal UX if we really think about it: e.g. if you select a file using a system-provided file picker it would automatically grant access to that file, as access is explicitly authorized.

Comments

Panzerschrek•1h ago
I presume this is because of compatibility reasons.

Back in 70s and 80s computers didn't contain valuable information to care about and there was no Internet to transmit such information. So, adding some sort of security elements in operating systems had no sense. In these years modern operating system were first developed - Unix, Dos, Windows. Since then many architectural decisions of these operating systems weren't revised in order to avoid breaking backward-compatibility. Even if we need to break it to achieve better security, no one is ready to make such sacrifice.

There are projects of operating systems with focus on security, which are not just Unix-like systems or Windows clones. But they can't replace existing operating systems because of network effects (it's unpractical to use a system nobody else uses).

A Survey of Reinforcement Learning for Large Reasoning Models

https://arxiv.org/abs/2509.08827
1•Anon84•54s ago•0 comments

Mango

https://www.google.com/?pli=1&safe=active&ssui=on
1•monkbal•1m ago•0 comments

YouTube Targets Creators and Consumers in Broad Generative AI Push

https://www.bloomberg.com/news/articles/2025-09-16/youtube-targets-creators-and-consumers-in-broa...
1•toomuchtodo•2m ago•1 comments

Pi Fractal [video]

https://www.youtube.com/watch?v=M8BrmqwdgNk
1•sd9•2m ago•0 comments

Workday to acquire AI startup Sana for $1.1B

https://sifted.eu/articles/workday-sana-acquisition
2•felix089•2m ago•0 comments

Trump's deportations divert FBI agents off child predator cases

https://www.msnbc.com/msnbc/news/trumps-deportations-divert-fbi-agents-child-predator-cases-rcna2...
3•throw0101d•4m ago•1 comments

Updated Thoughts on Trust Scaling

https://lucumr.pocoo.org/2019/7/29/dependency-scaling/
1•the_mitsuhiko•4m ago•0 comments

ROCm 7.0

https://rocm.docs.amd.com/en/latest/index.html
2•asparagui•6m ago•0 comments

Google's AI Agent Payments Protocol (AP2)

https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-prot...
1•schwentkerr•8m ago•1 comments

Daily Startup Newsletter

https://www.minimumviablenl.com/
1•minimumviable•8m ago•0 comments

Fifty Things you can do with a Software Defined Radio

https://blinry.org/50-things-with-sdr/
4•mihau•9m ago•0 comments

Samsung smart fridge displaying advertisements

https://www.reddit.com/r/homeassistant/s/OVP4LqiLAv
3•saeedesmaili•11m ago•1 comments

Show HN: ModelKombat – arena-style battles for coding models

https://astra.hackerrank.com/model-kombat
2•rvivek•12m ago•0 comments

Show HN: I wrote a from-scratch OS to serve my blog

https://github.com/thass0/tatix
1•thasso•12m ago•0 comments

Robert Redford, actor, director, environmentalist, dead at 89 – CNN

https://www.cnn.com/2025/09/16/entertainment/robert-redford-death
1•signa11•14m ago•1 comments

WebKit Features in Safari 26.0

https://webkit.org/blog/17333/webkit-features-in-safari-26-0/
1•ksec•14m ago•0 comments

Running a web server on a disposable vape

https://www.theregister.com/2025/09/15/nicotine_vape_web_server/
1•canbus•14m ago•0 comments

Local,private emotion detection API for text,powered by fine-tuned Gemma model

https://github.com/stevef1uk/emotion-server-demo/blob/master/README.md
1•apiemotion•15m ago•1 comments

Workday to Acquire Sana for $1.1B

https://sanalabs.com/
2•warthog•16m ago•0 comments

NeuroPilot – Your AI Study Companion

https://github.com/CaviraOSS/neuropilot
1•Boblaw1•17m ago•1 comments

Cycles in Marsaglia's Mental RNG

https://www.johndcook.com/blog/2025/09/16/cycles-in-mental-rng/
1•ibobev•17m ago•0 comments

Monero's Seed Phrase Words

https://www.johndcook.com/blog/2025/09/16/monero-seed-words/
1•ibobev•18m ago•0 comments

Robert Redford dead: passes away aged 89

https://www.msn.com/en-us/movies/news/robert-redford-dead-hollywood-icon-passes-away-aged-89-as-t...
1•rock57•19m ago•1 comments

SpaceX built a docking system from bicycle parts

https://www.washingtonpost.com/technology/2025/09/15/spacex-dragon-musk-nasa-space-station/
2•ryzvonusef•19m ago•2 comments

The 14kb Problem

https://joeldare.com/the-14kb-problem
2•codazoda•20m ago•0 comments

Early GenAI Researcher AI: I'm tired of the consciousness debate

https://fortune.com/2025/09/10/what-is-consciousnous-human-artificial-intelligence-tech-addiction/
1•ryan_j_naughton•20m ago•0 comments

Show HN: Port42 – AI agents that build tools from your actual work patterns

https://port42.ai/
1•gordonmattey•21m ago•1 comments

Building Towards Age Prediction

https://openai.com/index/building-towards-age-prediction/
1•wertyk•23m ago•0 comments

Parties' (Non)Responses to Economic Inequality, 1970–2020

https://www.cambridge.org/core/journals/american-political-science-review/article/why-inequalitie...
2•PaulHoule•24m ago•0 comments

Mother of All Demos

https://wordspike.com/s/5ip0xneiTsc
8•thekuanysh•26m ago•2 comments