3 ms·
> There are real mitigations (W^X, ASLR, stack cookies) We've had these for nearly a decade with other software. Have they completely stopped bugs/exploits in
by ryuuchin 10y ago
> There are real mitigations (W^X, ASLR, stack cookies)
We've had these for nearly a decade with other software. Have they completely stopped bugs/exploits in that time?
I'm not trying to take away from the usefulness of those mitigations against certain classes of exploits but the point of "lore" such as sandboxing is to promote defense in depth. If there's a buffer overflow which is exploitable then containing that in a restricted sandbox with no permissions to do anything requires more work to break out of.