4 ms·
Which security risks are you talking about? In the spec or in the implementations? Currently, the biggest security risk in WebGL is, indirectly, your graphics
by cscheid 13y ago
Which security risks are you talking about? In the spec or in the implementations?
Currently, the biggest security risk in WebGL is, indirectly, your graphics driver. As an example, the latest security problem with WebGL was in OS X and had to to with exposing uninitialized memory contents. Of course, it is true that graphics driver writers are only now warming up to the fact that a webpage shouldn't cause a kernel panic and that it shouldn't leak uninitialized memory. Still, the WebGL spec itself has fixed all of the early problems it had.
Sorry if you were aware of this distinction! I hear many people talking about WebGL security issues as they existed in the draft, and I think some clarification of the public opinion is in order.
- eridius 13y agoI'm talking about the OpenGL drivers. They were never intended to be exposed to untrusted code running on web pages, so they haven't really been hardened appropriately.
- cscheid 13y agoHave you given it a shot recently? I work with WebGL on a daily basis, and they are incomparably better now than they were not even 2 years ago. (And, to be perfectly nitpicky, in Windows you'd be blaming Direct3D drivers ;) ANGLE compiles WebGL to Direct3D.)
- snotrockets 13y agoOnly to untrusted binaries on your machine. Not caring about attacks from the local user is what got Microsoft tons of (justified) bad PR not ten years ago.
- eridius 13y agoOnce you're running an untrusted binary on your machine, the game's already over.
- deleted 13y ago[deleted]