5 ms·
Add operating systems, servers, and languages to your list for completeness. The reason they are unsafe is because they are created by humans, who make mistake
by samspot 12y ago
Add operating systems, servers, and languages to your list for completeness. The reason they are unsafe is because they are created by humans, who make mistakes. You are basically proposing that all technology innovation should cease until these things are 100% secure.
- whichfawkes 12y agoWe just have to accept the trade-offs of functionality. Things like airplane autopilot systems and medical equipment are probably pretty close to perfect, but that level of correctness in your browser, much less your operating system, much less your hardware - would be very costly. Even if every computer was running an operating system that was developed as carefully as equipment in charge of people's lives, I'm sure there'd still be vulnerabilities. The low hanging fruit is relative, and there'll always be people cracking computers.
- deleted 12y ago[deleted]
- mike_hearn 12y agoI think it's more like saying maybe before massively increasing the browser attack surface we should consider if it's really the right thing to do. A lot of sandbox escapes in recent years have been in very rarely used features like WebGL and Native Client. Cool tech for sure, but also big new exploit zones. The main problem is that what used to be called "mobile code" before smartphones were a thing is really convenient. That's why Java tried it too. Sandboxed code helps a lot, so there's this constant tension between trying to make the sandbox less restrictive and keeping it secure. Sometimes I think that despite poor execution the JVM guys had the right idea. Sandbox code from the net, but also have code signing to fall back on.
- greggman 12y agoCare to back that up? Please list this "lot" of WebGL and Native Client exploits. AFAIK there's been < 5 total over 5 years. Compared to the total number of exploits that's certainly doesn't seem like WebGL nor Native Client are an issue. As for rarely used, I'd guess Google Maps is a pretty well used site that uses WebGL.
- mike_hearn 12y agoWell, just search for "webgl cve", there seem to be quite a few. It exposes 3D drivers to untrusted code, and they can run to millions of lines of code. You're right, Google Maps is a good example of WebGL use. But it could also just be a regular desktop app. People would download it just fine.