3 ms·
Isn't Google's Native Client exactly an example of a safe bytecode? Moreover, it is a safe subset of an already existing really large byte code language (x86 ma
by maggit 11y ago
Isn't Google's Native Client exactly an example of a safe bytecode? Moreover, it is a safe subset of an already existing really large byte code language (x86 machine code), which inspires me to believe that it should be possible to identify similar subsets that are statically verifiable for other, especially simpler, byte code languages.
- sanxiyn 11y agoMany holes were discovered in Native Client. Difference is that Google was willing to fix them as they were discovered. For example, https://developer.chrome.com/native-client/community/security-contest https://developer.chrome.com/native-client/community/securit... lists 20 holes. I think the actual number of explicitly discovered holes in CPython and Lua bytecodes are each less than 20, and that was enough for them to give up.
- kuschku 11y agoGoogle's Sandbox will also show more and more holes every day. Because it's a comparably easy target, especially with x86 being so complicated and even having undocumented Opcodes. Even just mov or lea are Turing complete.