3 ms·
Which to me is a big yawn because as long as we have javascript engines in our browsers this will probably be possible. Browsing websites is basically an RCE an
by 693471 7y ago
Which to me is a big yawn because as long as we have javascript engines in our browsers this will probably be possible. Browsing websites is basically an RCE anyway.
- saagarjha 7y agoThe point of a browser's security model is to make it so that "remote code execution" does not mean "arbitrary remote code execution with elevated privileges".
- 693471 7y agoIf we really cared we'd only ship data and not code
- saagarjha 7y agoThat's assuming that parsers don't have bugs in them.
- lonelappde 7y agoCode is data. There is no technical difference, only human interpretative models.
- jcranberry 7y agoHe's obviously talking about shipping only non-executable data.
- minty_phoenix 7y agoI remember having been able to jailbreak my iPhone 3GS for a period of time entirely through visiting a website and letting it exploit such vulnerabilities enough to perform the task. Searching for a related article, appears to have been possible on iOS 4.0/4.0.1: https://www.cultofmac.com/53323/jailbreakme-2-0-jailbreaks-iphone-4-3gs-and-3g-on-ios-4-4-0-1-and-ipad-on-ios-3-2-1/ https://www.cultofmac.com/53323/jailbreakme-2-0-jailbreaks-i... Edit: I use ‘letting’ above loosely meaning that the specific website mentioned allowed the visitor to control whether the exploit was actually executed or not.