4 ms·
This article explores how Drupal can benefit from the capabilities-based security model offered by WebAssembly, a portable binary format that allows execution o
by gzurl 3y ago
This article explores how Drupal can benefit from the capabilities-based security model offered by WebAssembly, a portable binary format that allows execution of code in a safe and efficient manner. By deploying Drupal within a WebAssembly-based stack, it gains an additional security layer, protecting against a wide range of vulnerabilities, including those that may not be public yet but can be preemptively mitigated through these mechanisms.
- capableweb 3y ago> capabilities-based security model offered by WebAssembly What? Since when does WebAssembly natively ship with a "capabilities-based security model"? > protecting against a wide range of vulnerabilities, including those that may not be public yet but can be preemptively mitigated through these mechanisms Not yet public vulnerabilities? Who was this article/summary written by? Reeks of GPT or at least someone who doesn't actually know the subject very well.
- ridruejo 3y agoCapabilities based means that by default Wasm cannot do anything with the outside world. You have to explicitly declare the specific access you are giving, for example if the runtime implements WASI filesystem access you need to specify which parts of the underlying filesystem will be accessible to the module Not yet public means exactly that. You may have a buffer overflow issue in your code that you are unaware of. There are technologies that help mitigate those when/if discovered. Wasm is one of them but not the only one (ie most modern compilers have specific settings to harden the binaries against some issues)
- have_faith 3y agoI'm 99% sure this was written by some flavour of GPT.
- gzurl 3y agoYes, sure. WasmGPT this time :-)