4 ms·
That's exactly why I started scratching my head as to why the web entire security model assumes a trusted execution environment. That no longer makes sense in t
by Gxtaillon 5y ago
That's exactly why I started scratching my head as to why the web entire security model assumes a trusted execution environment. That no longer makes sense in today's world.
Naively to me it looks like it's an artifact of 90s OS security model. The modern web, and the threats of the modern world require more stringent security facilities at the OS level to allow isolation of security context even to super users and specifically per program-origin, per identity, and per-process context isolation. Super users having the ability to read-write in any security context is no longer appropriate, at most super users should only be able to deny and delete, that's the only way to protect end-user privacy.
- saagarjha 5y agoThis is largely how iOS works.
- fsflover 5y agoQubes OS [0] is based on a different security model: security through compartmentalization. [0] https://www.qubes-os.org/ https://www.qubes-os.org/
- beermonster 5y agoI can't find a link to it now, but there was a blogpost on how all other non-compartmentalization approaches to security had failed.
- fsflover 5y agohttps://www.qubes-os.org/faq/#what-about-other-approaches-to-security https://www.qubes-os.org/faq/#what-about-other-approaches-to...
- beermonster 5y agoThat’s the one! :)
- UncleMeat 5y agoSandbox escapes are part of most serious exploit chains nowadays. They make things harder for exploit authors but absolutely do not fix the problem at a fundamental level. iMessage runs in a sandboxed environment. Doesn't stop the exploit in the article from getting root.