3 ms·
Not even remotely. WASM uses the same sandboxed DOM APIs JS does, that's a huge difference compared to Applets or ActiveX.
by reader_mode 5y ago
Not even remotely. WASM uses the same sandboxed DOM APIs JS does, that's a huge difference compared to Applets or ActiveX.
- pjmlp 5y agoAlmost, "Everything Old is New Again: Binary Security of WebAssembly" https://www.usenix.org/conference/usenixsecurity20/presentation/lehmann https://www.usenix.org/conference/usenixsecurity20/presentat...
- reader_mode 5y agoFrom what I saw that's just about exploiting WASM memory within the sandbox - like they say "at wrost WASM can make a mess of it's own memory" and they show some implications of that. That's mildly interesting to me, you still need to go through DOM to do anything system related - you can't just read random files off of disk or use some system API to exploit other parts of the system. If API security is broken for WASM it's broken for JS as well. That's completely different from having a separate sandbox running as a native extension.