3 ms·
Browsers run it in a sandbox process together with allocator hardening. Most of the bugs then are just crashed of the sandbox Another option is WASM or WASM-st
by fpoling 4mo ago
Browsers run it in a sandbox process together with allocator hardening. Most of the bugs then are just crashed of the sandbox
Another option is WASM or WASM-style sandboxes if using another process is undesirable.
- johnnythunder 4mo agoOne chained sandbox escape away from compromise.
- ttoinou 4mo agoAhah But are the compiler+OS that runs the ffmpeg executable really a sandbox ?
- fpoling 4mo agoFor executables on Linux there are things like bubblewrap or firejail. One can also use a restrictive container. But those are strictly weaker than browser sandboxes. The most secure way presently is to use qubes-os that allows to use a very hardened VM to run individual applications.
- loeg 4mo agoWhich is of course better than zero sandbox escapes.