4 ms·
Web assembly is extra code and complexity in a web browser compared to one without, so there are more potential vulnerabilities
by FastEatSlow 5y ago
Web assembly is extra code and complexity in a web browser compared to one without, so there are more potential vulnerabilities
- tester756 5y agoI don't buy it because you can apply same reasoning to every new / changed line of code, yet it ain't always true The question is, is WASM's security model / sandbox "safer" / "easier to actually execute" than JS'?
- vbezhenar 5y agoIt does not matter because JS is not going anywhere. Whether it’s more secure or not, it’s still additional attack surface.
- tester756 5y agoI believe it does Of course JS ain't gonna go anywhere now, but if popular JS frameworks started emitting WebAssembly behind the scenes, so devs could still write their JS(and C++/C#/etc) code, but it'd use WASM under the hood then that'd start process of the deprecation of JS. Which would mean that after all popular JS frameworks managed to migrate and popular sites adopted to this, then in ideal world you'd be able to turn off javascript and still use those sites/apps via WASM, not by default for everyone, but at least users that care would have an option to do so while still being able to use the web. You gotta start somewhere I'm wrong somewhere? or out of the touch with reality?
- dchest 5y agoPerhaps, you can start by learning what WASM is: https://developer.mozilla.org/en-US/docs/WebAssembly https://developer.mozilla.org/en-US/docs/WebAssembly As for vulnerabilities, here are nccgroup's slides about WASM explots: https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-WebAssembly-A-New-World-of-Native_Exploits-On-The-Web.pdf https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-... Here's an example vulnerability in WASM parsing leading to RCE: https://labs.f-secure.com/assets/BlogFiles/apple-safari-wasm-section-vuln-write-up-2018-04-16.pdf https://labs.f-secure.com/assets/BlogFiles/apple-safari-wasm...
- vbezhenar 5y agoIf we're talking about 20 years from now, nobody cares about popular frameworks. Huge majority of websites use old code and they must not break. Backwards compatibility of web is a huge deal. So deprecation of JS just will not happen in that period of time. What could happen is that browsers will support wasm natively and they'll translate JS into wasm. I'm not qualified enough to judge whether it would be possible to achieve current levels of JS performance with that approach, but theoretically it could be possible. In this case only wasm security will matter. But I did not hear about any kinds of those plans, those are just my wild speculations. So deprecating of JS is not going to happen anytime soon. Wasm will accompany JS and that's about it for the foreseeable future.
- azinman2 5y agoWASM _IS_ JS. Some browsers do things to make it run faster. JS runs in its own security sandbox and is already suppose to be safe. Browsers get exploited in all kinds of ways, and IIRC, there have been WASM-specific exploits as well in the past. Your question is non-sensical as is. I think you need to expand it to have people be less confused as to what you’re asking.