3 ms·
The Java sandbox was actually really close to something that worked well. If you look at the Java virtual machine, it's actually quite simple, and very easy to
by ezyang 14y ago
The Java sandbox was actually really close to something that worked well. If you look at the Java virtual machine, it's actually quite simple, and very easy to ensure that nothing "bad" happens. Where Java lost the battle was in the provisioning of APIs which, you know, actually let developers do things like draw windows or load trusted code dynamically: here, it suddenly became necessary to trust huge swaths of code to do the right thing, and the Java sandbox got fucked. If you look at all of the sandbox vulnerabilities, they are never "Oh, the JVM was implemented incorrectly" and always "Oh, some API wasn't implemented properly." That's the key observation.
- zzzeek 14y agoand browser.exe would make none of these mistakes because..... ?
- ezyang 14y agoBecause it's untrusted: it runs in the sandbox.
- snatch_backside 14y agoThat seems like a pretty elegant solution.
- moe 14y agoSandboxes all the way down. Cf. Chrome.
- dredmorbius 14y agoThe other place Java lost the battle was in sticking to a closed, vendor-dictated implementation, that's slowly getting pulled into the massive hole of suck that is Oracle.