Hacker News new | past | comments | ask | show | jobs | submit login

To do it intentionally, sure, but don't worry, it'll happen whether they intend it or not.



I highly doubt.

They don't even allow emulators in iOS.

It took EU a decade to make Apple allow third party stores and even then Apple hasn't really complied still.

Same for browser engines.


M2 onwards has silicon support for nested virtualization. iOS 17 uses "Secure eXclaves" to isolate some code, which may be similar to the Android 14 pKVM use of nested virtualiation, https://android-developers.googleblog.com/2023/12/virtual-ma...

  With AVF virtual machines become a core construct of the Android operating system, similar to the way Android utilizes Linux processes. Developers have the flexibility to choose the level of isolation for a virtual machine:

  One-way isolation: Android (the host) can control and inspect the contents of the VM. These are most commonly used for sandboxing and separation..

  Two-way isolation (Isolated VM): Android (the host) and the virtual machine (the guest) are completely isolated from each other.. This has 2 main properties:

    1. The workload and data inside the VM is inaccessible (confidential) from the host (Android). 
    2. Even if Android is compromised all the way up to (and including) the host kernel, the isolated VM remains uncompromised.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: