3 ms·
> Conclusion: > * Programming language implementations cannot establish confidentiality on today's hardware > * Don't run untrusted code in the same process w
by bakery2k 7y ago
> Conclusion:
> * Programming language implementations cannot establish confidentiality on today's hardware
> * Don't run untrusted code in the same process with secrets it could steal
I understand that because of this, browsers are moving towards running untrusted JavaScript code in separate processes, so that confidentiality is provided by process boundaries.
Does anyone know whether other applications that embed scripting languages and run untrusted code (e.g. games that embed Lua[JIT]) are also moving towards a multi-process architecture?
- saagarjha 7y agoDoesn't Spectre work across process boundaries?
- nsajko 7y agoI think you mean Meltdown. https://en.wikipedia.org/wiki/Meltdown_(security_vulnerability) https://en.wikipedia.org/wiki/Meltdown_(security_vulnerabili...
- saagarjha 7y agoNo. Meltdown allows for reading kernel memory, subverting traditional memory isolation techniques. Spectre abuses speculative execution to perform side-channel attacks to leak information in general, including across process boundaries.
- deleted 7y ago[deleted]
- nsajko 7y agoRegarding Chromium, Site isolation has been enabled by default since last year in Chrome 67. https://www.chromium.org/developers/design-documents/site-isolation https://www.chromium.org/developers/design-documents/site-is... https://www.chromium.org/Home/chromium-security/ssca https://www.chromium.org/Home/chromium-security/ssca https://security.googleblog.com/2018/07/mitigating-spectre-with-site-isolation.html https://security.googleblog.com/2018/07/mitigating-spectre-w... https://www.chromium.org/Home/chromium-security/site-isolation https://www.chromium.org/Home/chromium-security/site-isolati...
- zzzcpan 7y ago> I understand that because of this, browsers are moving towards running untrusted JavaScript code in separate processes, so that confidentiality is provided by process boundaries. Google was moving on that feature before Spectre. Confidentiality is a rather strong word here. Web pages literally include random 3rd party code to run within the same process and that isolation on top of process boundaries doesn't address that, it's only addressing some hypothetical threat of a tab or a child frame stealing data and I'm not sure whether they even isolate child frames (EDIT: they try). A tab stealing data is too remote of a possibility if at all practical and 3rd party child frames are usually created by 3rd party javascript already running within process boundaries, so no confidentiality there. It's possible that some 3rd parties may want to sandbox the code they let other 3rd parties run in your browser, but that does nothing to guarantee any confidentiality. It's not that bad for newly designed languages or for languages willing to break compatibility. There are multiple approaches that can be used to protect from Spectre within the same process, plenty of ideas floating around.