4 ms·
Security has been a focus of NaCl from the outset. It uses a sandbox security model built around a restricted set of "native code". The aim was to make NaCl app
by werrett 16y ago
Security has been a focus of NaCl from the outset. It uses a sandbox security model built around a restricted set of "native code". The aim was to make NaCl apps verifiable from a security stand point.
Chris Rohlf from Matasano did a great blog post, The Security Implications Of Google Native Client, that compares the NaCl approach to ActiveX and Java -- and included beautiful diagrams to boot! Unfortunately the images appear to be broken on the Matasano blog [1] but I've found a PDF'd version [2] that contains them in all their glory.
The post came out of the Matasano team's entry in the Native Client Security Contest [3] that Google held early last year. The Matasano team ended up taking second place behind Mark Dowd / Ben Hawkes [4]. All those guys are 'rockstars' in the security industry.
So, Google has thought deeply and tried hard when designing NaCl's security. They a care enough and are switched on enough to run a security contest that was well received by the industry (rare). A number of mega-brains-on-sticks found issues back in May '09 -- hopefully they have all been addressed.
It looks to me that Google has done a good job at learning from past mistakes when implementing NaCl and it should be different. No doubt there will be further security issues found but then again, name a framework that is free from flaws?
[1] http://chargen.matasano.com/chargen/2009/8/27/the-security-implications-of-google-native-client.html http://chargen.matasano.com/chargen/2009/8/27/the-security-i...
[2] http://beefchunk.com/documentation/security/the_security_implications_of_google_native_client.pdf http://beefchunk.com/documentation/security/the_security_imp...
[3] http://code.google.com/contests/nativeclient-security/index-old.html http://code.google.com/contests/nativeclient-security/index-...
[4] http://code.google.com/contests/nativeclient-security/index.html http://code.google.com/contests/nativeclient-security/index....