3 ms·
This has some heavy hitters behind it, both in authorship and their organizations. I wondered how it compares to Caja, and this is what their "Towards .." pape
by mahmud 12y ago
This has some heavy hitters behind it, both in authorship and their organizations.
I wondered how it compares to Caja, and this is what their "Towards .." paper states:
"Caja, ADSafe, and FBJS offer sandboxing by defining safe subsets of JavaScript; these subsets tend not to support JavaScript’s full functionality, and as retrofits atop existing browser interfaces, they are also vulnerable to various attacks"
- hackerweb 12y agoCaja is something you can do server-side to filter JavaScript. COWL is a modification to the browser security architecture. Hence, unlike Caja, a web site cannot unilaterally deploy COWL. On the other hand, if COWL or something like it makes it through the standardization process, it would have a far more significant impact on web security than Caja.
- nl 12y agoCaja is (more?) often deployed on the client side to filter Javascript.
- ezyang 12y agoJavaScript sandboxing is a sort of orthogonal concern to what Cowl is after. Cowl needs sandboxing to work (either by built-in browser support, or by Caja et al), but even with a sandbox, you still need some sort of policy for when to allow data in and out of the scripts, and that's one of the main things Cowl provides.