frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Unikernels were hard. key word: were

https://ghuntley.com/unikernels/
17•ghuntley•5h ago

Comments

eyberg•4h ago
Reducing attack surface is definitely a plus but it is nowhere close to the number one security benefit of running unikernels.

That's why I never really liked talking about "reducing attack surface" that much because folk inevitably turn to lines and code, which while reducing is good, just simply doesn't communicate what the biggest problem truly is.

Vuln exploitation is the number one entry point for data breaches and os command injection is the number one CWE in CISA Kev from last year.

System intrusion was repeated something like 64 times in last year's DBIR.

The operating system itself is literally the problem as it's inherently meant to run many different programs whereas unikernels only run one.

fsflover•51m ago
> The operating system itself is literally the problem as it's inherently meant to run many different programs whereas unikernels only run one.

Unless you rely on security through compartmentalization. See: https://qubes-os.org

terabytest•1h ago
I’m completely ignorant about this and likely just missing the point but: isn’t the point of an OS to not have to (vibe)code filesystems and networking by hand every time you need them? Also, how does a unikernel cooperate with other applications? Would they all live in separate networked unikernels managed by a hypervisor? And, if they all (vibe)coded their own fs and network wouldn’t that introduce subtle bugs and inconsistencies that would eventually bring the whole thing down and lead you back to the need for shared primitives in the first place?

Maybe a good halfway point is to still have a unikernel but the libraries for common stuff like networking or fs are already written according to a standard and plug and play and reusable across applications?

cmrdporcupine•47m ago
You don't build the networking or filesystem by hand every time you need them. You pull them from reviewed and maintained library code from a repository. That's how MirageOS etc work. Someone else has written e.g. TCP/IP -- hopefully well -- and you link against it.

The point that makes this different from an OS is that there's no shared service, no syscalls to do that stuff -- just subroutine calls -- and no timesharing (except at the hypervisor level). It's just a single runtime running on hypervisor direct against the virtualized hardware.

Because, yeah, all this work has happened in hardware in the last 30 years to make that possible, but we still treat the operating system as the best unit of resource sharing. When in fact it's kind of a jack of all trades master of none. If you're booting a whole linux kernel -- with its giant framework built to co-tenant a pile of applications and users -- just to run one process, there's definitely something to look at there. Even if the unikernel space itself is relatively immature.

You don't need to emphasize the "vibe coded every time you need them" thing. That's not what anybody was being talked about in the article. The "vibe coding" piece is pointing out that the missing pieces in the ecosystem can be more rapidly filled in now because of agentic tooling.

dist1ll•41m ago
Unikernels simply redraw abstraction boundaries. You can still use libraries and third-party code to implement common primitives. In fact, that's exactly what many unikernel frameworks give you (unikraft, hermit, mirage)
jauntywundrkind•43m ago
I do wonder what kind of wins we're going to see from unikernels.

I used to regard V8 Isolates as a best possible sort of technology, with userlands juggling lots of processes.

Seeing netlify & unikraft switch to microvm's and have such a huge speed up was a bit of an awakening for me. Those are really fast start times! https://www.netlify.com/blog/edge-functions-firecracker-micr... https://unikraft.com/customer-stories/edge-functions-netlify...

Intuitively, I think I have some appreciation for how much silicon has been poured into virtualization. Its always seemed like a "yeah but you could avoid those costs by not doing that" but I'm more receptive to the idea that these might in some cases be really good ways to get some of the isolation workloads demand with the hardware helping us out, these days. There's so much securing for vm's, and maybe it's just easier than trying to secure in userlands: let the hardware help.

Long time interest in microvm's but they felt heavier weight than I wanted. Now it feels like maybe they might actually in some regards in some ways be lighter weight than managing workloads yourself in userland. Maybe. I dunno. Interesting times, i'm open to it.

cmrdporcupine•38m ago
One of the problems is there's only a small certain percentage of scenarios/applications that benefit from very short start times.

I'd wager most of the services running on the interwebs are web servers, database servers, inference servers etc that don't change over their lifetime really. They're just doing the same thing all day long every day.

If you're doing stuff like what I'm doing for work right now, which is, yeah, multiplexing potentially oodles of user-submitted jobs, and those jobs are best expressed as distinct images or containers, then yes, managing start times is absolutely imperative in improving utilization/occupancy and therefore reducing costs.

But I'm not convinced that's a typical scenario, not typical enough to drive enough time and money investment in this space maybe?

Also there ain't currently no real "hypervisor" for the (NVIDIA) GPU. Not practically anyways. And that's arguably where we need it the most. Or at least I do, for Day Job(tm).

So unikernels and microvms may have to lean on other arguments for adoption: security and simplicity-to-reason-about might be those...

vsgherzi•22m ago
As mentioned before on this topic. What about debug ability? An application overflow now corrupts part of the network stack.

In an oxide episode there were some mentions of reading off data lines but I just don’t think that’s practical.

The reduced attack service is cool but not at the expense of my visibility and liveness of the system

cmrdporcupine•18m ago
Yeah that's generally the argument for using a managed runtime (like Ocaml in MirageOS's case, or I could see Go or even the JVM fitting here) for these kinds of things. Running a VM which has no pointers, memory access etc primitives, and is garbage collected etc direct on "metal" gives more peace of mind about that sort of thing.

You could make the argument that Rust w/ its memory safety is a candidate, but w/ Rust it's still entirely possible and fairly easy to break out of that. And Rust/Cargo applications have a habit of using a bazillion third party deps that you then need to keep a close eye on.

lasiotus•5m ago
Unikernels are on the smaller side of the spectrum; Linux on the larger side, with a lot of room in the middle...

2D Vehicles

https://patkerr.co.uk/2d-vehicles/
63•Michelangelo11•3d ago•13 comments

Knuth reward check

https://www.thomas-huehn.com/knuth-reward-check/
88•Curiositry•4h ago•32 comments

Talorys – A self-hosted personal AI agent on Cloudflare's free tier

https://github.com/rociiu/talorys
196•rociiu•8h ago•101 comments

Why DuckDB 2.0 is faster

https://motherduck.com/blog/why-duckdb-20-is-faster/
15•tosh•1h ago•1 comments

Nvidia in talks to acquire US 'open' model startup Reflection AI

https://www.ft.com/content/052610c5-22b4-4dd4-932e-b7f9f0628b6a
29•arkj•59m ago•15 comments

Grieving the Loss of Details

https://purplesyringa.moe/blog/grieving-the-loss-of-details/
223•signa11•4d ago•157 comments

Apple/macOS removed from official Unix registry

https://www.opengroup.org//openbrand/register/
183•john_alan•8h ago•173 comments

Mxc: Microsoft Execution Containers version 1.0.0

https://blogs.windows.com/windowsdeveloper/2026/10/07/microsoft-execution-containers-policy-drive...
109•smokel•1d ago•21 comments

Rampart: Browser native on-device PII radaction

https://ndstudio.gov/posts/say-hello-to-rampart
51•nateb2022•1d ago•19 comments

REA Reverse – Engineer Anything

https://rea.tools/
632•modinfo•19h ago•272 comments

Bitwarden Dual License Model

https://community.bitwarden.com/t/published-version-update-in-app-stores/102750
272•Cider9986•5h ago•205 comments

Telegram Desktop vulnerability allowed any user's file to be stolen

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
358•g-b-r•16h ago•194 comments

Vibe coded browser ports of Halo, The Simpsons: Hit And Run, GTA work well

https://kotaku.com/we-might-be-cooked-as-these-vibe-coded-web-browser-ports-of-halo-the-simpsons-...
39•astlouis44•1h ago•29 comments

Triple-A Minesweeper

https://minesweeper.mikelacher.com/
1297•robin_reala•1d ago•257 comments

I would like the value of my home to rise, while my property taxes fall

https://conversableeconomist.com/2026/09/28/i-would-like-the-value-of-my-home-to-rise-while-my-pr...
151•colinprince•6h ago•326 comments

Takeshi's Castle

https://en.wikipedia.org/wiki/Takeshi%27s_Castle
17•tosh•34m ago•5 comments

OpenSCAD the Programmers Solid 3D CAD Modeller

https://openscad.org/
42•b-man•3d ago•41 comments

PVX-001: open-source Covid-19 vaccine starts Phase 1 trial

https://chronicles.popvax.com/p/popvax-goes-clinical
83•jajoosam•4h ago•16 comments

Nix wrote half of my debugger

https://fzakaria.com/2026/10/07/nix-wrote-half-of-my-debugger
3•ingve•1d ago•0 comments

Chernobyl particles reveal unexpectedly stable nuclear fuel after 40 years

https://phys.org/news/2026-10-chernobyl-particles-reveal-unexpectedly-stable.html
105•geox•3d ago•34 comments

Eye of Sauron: Long-Range Hidden Spy Camera Detection (2024)

https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-qibo
273•ortusdux•3d ago•62 comments

`123456' password used in Danish CPR data breach

https://cphpost.dk/2026-10-10/news/round-up/123456-password-used-in-massive-danish-cpr-data-breach/
348•baal80spam•9h ago•181 comments

Whooping Cranes Learned to Migrate by Following Costumed Pilots

https://theverifiedpost.com/article/whooping-cranes-ultralight-costumed-pilots-operation-migration
32•kgolubic•1d ago•4 comments

Unikernels were hard. key word: were

https://ghuntley.com/unikernels/
17•ghuntley•5h ago•10 comments

FDA may allow some toxic chemicals to be added to food without safety review

https://www.theguardian.com/us-news/2026/oct/10/fda-toxic-chemicals-food-analysis
119•NewJazz•4h ago•60 comments

WSL3 Performance is about 5-60% faster than WSL2 depending on the workload

https://tonym.us/wsl2-vs-wsl3-benchmarks.html
215•tonymet•2d ago•190 comments

Can you use autoregressive diffusion to generate market data?

https://blog.janestreet.com/can-you-use-autoregressive-diffusion-to-generate-market-data/
161•jsomers•1d ago•52 comments

Noto means "no tofu": fixing dotted circles in Myanmar text

https://www.datocms.com/blog/handling-less-common-scripts
46•steffoz•4d ago•29 comments

Cloudflare acquires Deno

https://deno.com/blog/cloudflare
1326•ilreb•1d ago•683 comments

Show HN: Carrier-Explode: iPhone, Pixel and Galaxy carrier settings decoded

https://carrierexplode.com/
397•simplyalec•1d ago•46 comments