4 ms·
The host application is still C, and the final compilation of the mix of C and sanitized C still relies on the optimizer to be fast, so it might be possible for
by Tobu 5y ago
The host application is still C, and the final compilation of the mix of C and sanitized C still relies on the optimizer to be fast, so it might be possible for the untrusted library to reveal UB in the rest of the application. I can see how the whole approach (wasm + taint) would make compromise of the sanitized bits through crafted data harder, but I'm not sure it does enough for guarding against a supply chain compromise of the library.
- Tobu 5y agoAnd I see the safe languages section[1] in the WasmBoxC post; that looks like it would address most of the remaining UB risk, but Firefox will take some time getting there. [1]: https://kripken.github.io/blog/wasm/2020/07/27/wasmboxc.html#safe-languages https://kripken.github.io/blog/wasm/2020/07/27/wasmboxc.html...