4 ms·
> Until OS vendors are willing to provide a safe sandbox to run untrusted code in Thing is, "safe" OS-sandboxes are not safe; "local" privilege escalation vuln
by 0815test 7y ago
> Until OS vendors are willing to provide a safe sandbox to run untrusted code in
Thing is, "safe" OS-sandboxes are not safe; "local" privilege escalation vulnerabilities are still pervasive. Until OS's are safe enough that I can run `sudo -u nobody untrusted_binary` and not even think about the possibility of it taking over my system, something like the WASM sandbox (perhaps extended with WASI and other optional mechanisms) will always be needed.
- danieldk 7y agoThe the browser sandbox is just another sandbox, as we have seen with targeted attacks on Firefox two weeks back. Why is everybody so insistent on running untrusted code?
- bitwize 7y agoBecause the Web won't work without running untrusted code.
- idle_zealot 7y agoThe Web of hyperlinked documents would still work. But webapps would not be able to run arbitrary code the moment they were navigated to. Perhaps there should be a clear user-visible distinction between an HTML document with some styling and a full-blown application (that happens to use DOM for layout).
- wtetzner 7y agoWho gets to decide which code is trusted?