3 ms·
What are your thoughts on file:// URLs being opened/executed in a separate enclave from the network, with no access to the network? This would allow the conven
by souterrain 7y ago
What are your thoughts on file:// URLs being opened/executed in a separate enclave from the network, with no access to the network?
This would allow the convenience of file:// and IMHO eliminate many if not all of the risks.
- codedokode 7y agoThis won't allow to load images, files from CDN etc.
- souterrain 7y agoCorrect. IMHO accessing the local filesystem is incompatible with accessing the network from a security standpoint. I’m fine with having a very clear toggle to allow this behavior for developer types, but this should default to secure.
- dTal 7y agoI think this summarizes the issue and is exactly the correct solution. There's a lot of the comments along the lines of "just run python -m SimpleHTTPServer" - but doing that makes your computer just as vulnerable as allowing file:// in the first place, in theory. It's only the very awkwardness of doing that that makes it any safer. Instead of hiding this fundamental incompatibility between security and local accessibility behind a layer of inconvenience, better to drag it out into the open and label it and fully support it. While you're at it, you can slacken off some of the other restrictions in "local mode" as well. A browser is the modern VM, for better or worse. It should function locally, standalone.
- est31 7y agoIt would improve security, but ultimately as long as the file "enclave" can execute javascript, it has access to enough side channels to communicate any data it collects to the outside, so I guess the security concerns wouldn't be fully resolved.
- lucideer 7y agoCan you elaborate on these side channels?
- est31 7y agoOne example: if two programs share the same CPU and have access to CPU resources, then one program could transmit information to another program by putting the CPU under load and removing the load again in some kind of morse code fashion. In computers with fans this would probably be noted by users but not every computer has fans. It's not a very high bandwidth way but enough to get ssh keys transmitted within a few hours of connection.