3 ms·
Ecosystems get it right because they have to. E.g. iOS and Android etc. This ain't so good on desktop systems. Probably the compiled program should just get tb
by coolcase 1y ago
Ecosystems get it right because they have to. E.g. iOS and Android etc. This ain't so good on desktop systems.
Probably the compiled program should just get tbe permissions it needs.
A simple capability system for libraries might be the good that is the enemy of perfect:
Pure - can only access compute and its own memory plus passed in parameters (needs immutable languages or serialization at interop)
Storage IO - Pure but can do Storage IO. IO on what? Anything the program has access to.
Network IO - similar concept
Desktop in Window - can do UI stuff in the window
Desktop General - models, notifications, new windows etc.
Etc...
Not very fine grained but many libraries cab be Pure.
It ain't perfect.
A Pure library that formats a string can still inject some nasty JS hoping that you'll use that string on a web page! Ultimately... useful computation is messy and you can't secure everything in advance through capabilities alone.
- ameliaquining 1y agoIIUC iOS and Android don't have library sandboxing; any code that you allow to run in your app's process can access the whole address space. Apps themselves are sandboxed, but that doesn't help with the class of problem that this post is about.
- pjmlp 1y agoAndroid surely has, although its adoption is currently optional. https://privacysandbox.google.com/private-advertising/sdk-runtime https://privacysandbox.google.com/private-advertising/sdk-ru...