3 ms·
Hello, one of the paper authors here. One of the jobs that our implementation has to do is close down all channels by which JavaScript could leak data: so this
by ezyang 12y ago
Hello, one of the paper authors here.
One of the jobs that our implementation has to do is close down all channels by which JavaScript could leak data: so this includes postMessage, the DOM, XHR, cookies, local storage... fortunately, these overt channels are well specified DOM APIs so from the implementor's perspective it's not too difficult to lock them all down. (And we just deny access, there's no "shadow" structure s involved.) There's nothing too fine grained going on: if you read private data, everything it isn't allowed to flow to is locked down.