4 ms·
> as safely as multiple sites can coexist in Chrome tabs Chrome tabs usually run in different processes. It sounds like Cloudflare is using JS isolates within
by xxgreg 8y ago
> as safely as multiple sites can coexist in Chrome tabs
Chrome tabs usually run in different processes. It sounds like Cloudflare is using JS isolates within the same process to run many customers.
This sounds scary to me. For security, the Chrome team assumes that any code running in the same process has access to the whole address space of that process due to all of the recent speculative execution issues (Spectre/Meltdown).
I've seen comments on HN say that this isn't a problem for cloudflare because they do special things with all of JS timing APIs and a few others to mitigate.
Will be interesting if they are able to make this secure. Millisecond cold startup times will be amazing for development.
- skrebbel 8y ago> This sounds scary to me. Well, maybe I'm wrong :-) my relationship with CloudFlare ends at me being a customer, there is a significant chance that my impression of how Workers (or its security setup) works is wrong. If you want to be sure, ask CF.
- xxgreg 8y agoIn the conclusion of a recent Spectre paper published by a number of Google security researchers they write: "The community has assumed for decades that programming language security enforced with static and dynamic checks could guarantee confidentiality between computations in the same address space. Our work has discovered there are numerous vulnerabilities in today’s languages that when run on today’s CPUs allow construction of the universal read gadget, which completely destroys language-enforced confidentiality" CloudFlare believes this doesn't apply to them and that they have created defences which allow them to run multiple customers' code in the same address space without leaking memory. I think the burden of proof is on CloudFlare, and I'm yet to see them actually publish any information about this.