3 ms·
> offer the functionality it has today while balancing with security and sandboxing. LoL, LoL, LoL You can say this only because every other operating system
by higerordermap 6y ago
> offer the functionality it has today while balancing with security and sandboxing.
LoL, LoL, LoL
You can say this only because every other operating system sucks at sandboxing.
There is no reason you have to be inefficient as browser to provide security and sandboxing. In return there is also a huge attack surface, with all the code running below, and corner cases in web standards. AFAIK any js click event can allow a website to read your clipboard. Websites can somehow prompt to add extensions to your browser etc.. I know there are legitimate reasons for this but it sandboxing is not exclusive virtue of web platform.
- alexhutcheson 6y agoWhat existing sandboxing systems are you thinking of that are more efficient? Would you be confident using them to run possibly malicious code on your system?
- shakna 6y agoBSD jails? I'd be quite confident running possibly dangerous code in one of the most restricted jail configs. Processes can't interact, can't access outside their given directories, can't modify devices, etc.
- deleted 6y ago[deleted]
- higerordermap 6y ago>> because every other OS sucks at sandboxing And I won't be confident using browser too. Pretty sure at any given time there will be quite a few javascript/wasm attacks which can escape browser sandbox and run arbitrary code, then my files won't be safe. When I am running potentially malicious website I am creating a separate user on my linux box anyway.