3 ms·
Nothing wrong with Rust, but I still think making operating systems with airtight sandboxing and proper permission enforcement is the only thing that can truly
by NohatCoder 5y ago
Nothing wrong with Rust, but I still think making operating systems with airtight sandboxing and proper permission enforcement is the only thing that can truly solve these issues.
- jl6 5y agoStill not enough, because apps still need to interact with the outside world, so there would have to be intentional holes in the sandbox out through which the compromised app could act maliciously.
- NohatCoder 5y agoThat is why you need a well designed permission system. Android and iOs had a chance of doing this in a time when the requirements could reasonably be understood, but I don't think either came close.
- anon_123g987 5y agoAnd what language should we use to create such an OS? Maybe Rust?
- NohatCoder 5y agoIt is a better choice than C++ for sure.
- malwarebytess 5y agoMay I humbly suggest Holy C? https://www.youtube.com/watch?v=BUrbyfzm6i0 https://www.youtube.com/watch?v=BUrbyfzm6i0 https://templeos.holyc.xyz/Wb/Doc/HolyC.html https://templeos.holyc.xyz/Wb/Doc/HolyC.html
- rcxdude 5y agoOnly if the barriers have a finer resolution than a single application. Most applications need access to more than enough data to cause problems in the case of an exploit. You need sandboxing between different components of the application as well.
- azinman2 5y agoLook at how often V8’s sandboxes get exploited. It’s all developed by humans, which means there will always be errors. Saying just make airtight sandboxes is like just write bug-free code.
- NohatCoder 5y agoIt is a tradeoff. Making an airtight sandbox is not that hard. Making it run programs near hardware speed is a lot harder. Making it run legacy machine code is a nightmare. JavaScript is not machine code, but still a good deal harder to make fast than a language designed for fast sandboxing. Of course there have been bugs, but mostly I think the JS VMs have done a pretty good job of protecting browsers.
- dagmx 5y agoI feel like those are two separate levels of concerns though. Airtight sandboxing would be easier in a memory safe language prevents certain classes of bugs.