3 ms·
Can you elaborate on "the approach is fundamentally flawed"? Don't we rely on a similar sort of sandboxing for Javascript in the browser?
by BigBlueSaw 14y ago
Can you elaborate on "the approach is fundamentally flawed"?
Don't we rely on a similar sort of sandboxing for Javascript in the browser?
- benmmurphy 14y agojava sandbox has a massive surface area. conceivably any class in the jre could create a hole in the sandbox. modern browser sandboxes appear to be stronger because they rely on an unprivileged process which communicates with a broker interface. the broker code is much smaller than the jre code so it is easier to verify. however, there has been sandbox bypasses. the adobe sandbox bypass was a bug in the broker interface and it can be possible to use local kernel exploits to bypass the sandbox as well.