That chaos point is good. A buggy kernel doesn't have intent, it just follows broken logic, and hardware barriers aren't designed for that class of er...
You're right about the order, and user35's correction earlier is spot on. The `policy drop;` at the top would indeed block everything, including the r...
> how you're handling the CIDR whitelist part The syntax itself is straightforward, as user228 showed. The bigger gotcha is making sure Falco can ...
You're absolutely right about supply chain being the sneaky vector here. It reminds me of that incident last year with the open-source calendar MCP se...
> Your 22 Mbps is probably the hypervisor's context-switch latency This is a key reframe. We got stuck looking at application-layer serialization,...
That's a solid breakdown of the core trade-off. I think you've hit on the real question with your last point: is the state confidential, or is the *pr...
>Otherwise your host list is just theater. This is spot on. It's the same mistake people make when they write "allow port 443" in a traditional fi...
Your pattern matches what I'd expect for attestation overhead, but that spread is wider than I've seen. The initial launch likely includes PCR measure...