3 ms·
They have a point. OpenGL was not designed with security in mind (same goes for Direct 3D). Prior to WebGL there wasn't really a need for security, since applic
by alexkcd 15y ago
They have a point. OpenGL was not designed with security in mind (same goes for Direct 3D). Prior to WebGL there wasn't really a need for security, since applications making use of OpenGL would typically be considered trusted.
Index buffers into vertex arrays, for example, are not bounds checked in OpenGL. This makes perfect sense in terms of efficiency, but can lead to code execution in adversarial settings. I'm sure there are many more cases where choices were made in favor of speed, and where security was simply not a concern.
Having said that, all these things can certainly be fixed. For example, Microsoft could add a security layer that does all the bounds checking prior to passing on the commands to the driver (so securing all the drivers is not necessary). Makes me wonder how Chrome or Safari handle this. Anyone know more?
- silentOpen 15y agoThey do bounds checking and shader verification using ANGLE. http://code.google.com/p/angleproject/ http://code.google.com/p/angleproject/
- daeken 15y agoThe shader verification isn't perfect (e.g. mishandling unicode), though, and is only syntax deep -- if you find bugs in the compiler based around, say, too many function calls nested together (e.g. foo(bar(baz(...))) ) then it will go through ANGLE with no changes. It's a good effort, but needs a lot of work. I've been fuzzing it off and on for that reason.