3 ms·
>Inappropriate translation would result in a direct exploit unlike VM, since AFAIK there is no practical means to sandbox shaders. What does it mean to sandbox
by reader_mode 5y ago
>Inappropriate translation would result in a direct exploit unlike VM, since AFAIK there is no practical means to sandbox shaders.
What does it mean to sandbox shaders in this context ? GL ES shaders are sent down in a high level language and can't really do much besides do computation on input parameters to generate output in a pipeline. I wish they were more general purpose and worthy of sandboxing but the web GL shaders are really limited.
- pjmlp 5y agoWell, not so. https://www.contextis.com/us/blog/webgl-more-webgl-security-flaws https://www.contextis.com/us/blog/webgl-more-webgl-security-... https://www.hpcwire.com/2018/05/31/gpus-excellent-performance-but-what-about-security/ https://www.hpcwire.com/2018/05/31/gpus-excellent-performanc... https://www.cs.utexas.edu/users/witchel/pubs/zhu17gpgpu-security.pdf https://www.cs.utexas.edu/users/witchel/pubs/zhu17gpgpu-secu...
- reader_mode 5y agoFirst link demonstrates reading from uncleared buffered to capture screen contents - and is from Windows XP era. Second one is about running a bitcoin miner on the GPU, hypothetical memory breaches, and GPU DoS. You can stall the graphics pipeline without shaders, run a miner on CPU, and I'm going to need a demonstration of a usefull GPU memory breach with WebGL. On top of that any such breach is likely driver dependent and will only work on some specific driver/HW combination - that's such a low attack surface I doubt anyone will bother developing exploits targeting that. I didn't bother going through third because I wasted enough time on first and second, I don't see how anything here suggest you need to sandbox shaders.
- pjmlp 5y agoUntil it eventually happens on your computer I guess.