2 ms·
Because downloading and running binaries of applications is much safer? From what i've seen web browser teams have taken the recent risks extremely seriously -
by nullandvoid 7y ago
Because downloading and running binaries of applications is much safer?
From what i've seen web browser teams have taken the recent risks extremely seriously - I have sure had a worse track record of infection via downloading and installing software versus visiting sites with JS running
- yc12340 7y ago> web browser teams have taken the recent risks extremely seriously Not really. They didn't even properly apply band-aids. Chrome and Firefox disabled number of features, that allow Javascript code to create high-precision timers. This makes exploiting slightly more difficult, but the gaping hole is still there — there is infinite number of ways to create a high-precision timer, just not as obvious as closed ones. Chrome has enabled Site Isolation on desktop, but haven't done it on Android (presumably, because of associated increase in memory consumption). All major browsers still allow Javascript to run in background, create CPU threads and consume unrestricted amount of CPU time. I don't believe, that any of them have mounted instruction-based defenses (lfence etc.), but I may be mistaken here.