4 ms·
I see a future where the npm-style ecosystem develops with the JIT running inside the kernel, so you end up running a "trusted" application ends up running a wh
by twtw 8y ago
I see a future where the npm-style ecosystem develops with the JIT running inside the kernel, so you end up running a "trusted" application ends up running a whole lot of untrusted code via dependencies. Usually process isolation gives you some limit on how much damage something like that can do.
Also, if you are 100% sure that the code in it is trusted, then there really is no reason to sandbox it, right? If the intent is to only run trusted code, why is this article about spectre mitigations?
- kiriakasis 8y ago> if you are 100% sure that the code in it is trusted, then there really is no reason to sandbox it, right? If the intent is to only run trusted code, Trusted code can have bugs; sandboxing, in a sense, is always useful (not always beneficial)
- deleted 8y ago[deleted]