Microsoft has released LiteBox 0.1, the first version of its open-source, Rust-based Library OS designed to isolate applications from the underlying operating system, reducing access to host resources and limiting security risks.

Unlike a traditional operating system such as Linux or Windows, Library OS does not run independently or provide a complete environment for users. Instead, it implements operating system functionality as a library that applications use within a controlled execution environment.

In LiteBox’s case, the goal is to provide applications only the interfaces they need while minimizing interaction with the host operating system. This reduces the attack surface, meaning fewer ways for malicious or compromised software to interact with the underlying system.

LiteBox uses a modular architecture built around two interfaces: North and South. The North interface provides operating system functionality to applications through a Rust API inspired by the nix and rustix libraries. The South interface connects LiteBox to the underlying execution platform.

By separating these components, developers can combine different application interfaces with different platforms without redesigning the entire system.

Microsoft says LiteBox is intended to work in both kernel-mode and user-mode environments, allowing it to support several application isolation scenarios.

For Linux users, a relevant use case is sandboxing Linux applications directly on Linux. Another is running unmodified Linux programs on Windows, although LiteBox is not intended to replace WSL as a general-purpose Linux environment.

Beyond these scenarios, the project also targets more specialized security environments, including AMD SEV-SNP, which provides hardware-backed memory protection for virtual machines, and OP-TEE, an open-source trusted execution environment.

Microsoft additionally lists Linux Virtualization-Based Security among the supported use cases.

The project is still under active development. According to its maintainers, APIs and interfaces may change as the architecture matures. Developers requiring long-term stability are advised to wait for a stable release or be prepared to adapt their implementations.

LiteBox is available under the MIT license, with its source code, development information, and contribution guidelines hosted on GitHub.

For more information, visit the official LiteBox GitHub repository.

  • hoshikarakitaridia@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    1 day ago

    Damn they must be beyond desperate

    I am torn. I’m glad they’re trying genuinely new things and imo rewriting parts of their code in rust is a great idea performance-wise. I wish they would do it with the rest of the OS too.

    Then again why? We got Linux, we got permissions, we got security concepts and doctrines, we got users, groups and members and we got LDAP. We also have sandboxing through lxc or full on VMs. Maybe this is the only way to do it on windows but they’re just reinventing the wheel just so they can fit it on a donkey. It’s just kind of useless to tack that onto a swiss cheese of an OS.

    It feels like they know something fundamental has to change but they just invent new things to screw onto a rusted old contraption that’s barely humming along. This is kind of an “either commit or die pretending” moment and I am curious if they understand that before it’s too late and what a genuine strategy would look like.

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      Nothing will change until companies stop depending on software written for Windows 95 and kept up to date by the vendor just barely enough to keep working.