NT kernel engineer: Linux's messy permission model is a poor fit for AI agents

lauriewired · x · 2026-09-25

Security researcher lauriewired argues the NT kernel, with its coherent day-one security model, beats Linux whose SELinux, Capabilities and Namespaces are bolted-on patches. As users grant AI agents escalating system access, Linux's overlapping mix of UIDs, GIDs, ACLs, cgroups and filesystem modes makes it impossible to answer "what exactly is this agent allowed to do?" NT-style typed resources would enable strong centralized audit trails. He also muses that an "Open NT" in the early 2000s could have let companies like Amazon fork and customize the kernel safely. A greenfield kernel designed in 2026, he says, would look closer to NT or a BSD fork than Linux.

Original post →

More from AGI Musings

AGI Musings channel →