4 ms·
> In the end, this all is just reinventing the JVM, in slower, but more secure More secure?
by douche 9y ago
> In the end, this all is just reinventing the JVM, in slower, but more secure
More secure?
- jcranmer 9y agoProbably the biggest cause of security bugs in Java applets is the fact that the applet execution environment is a full JRE, with all the APIs involved in desktop JRE instances available, with "insecure" ones being locked down on an as-needed basis. So if a developer forgot to insert a security check in the JVM, the applet becomes able to subvert its sandbox. The browser VMs don't have these APIs available in the first place, so getting undesirable access to things like the filesystem is much more difficult than "spot the API with the missing check."