zlacker

[parent] [thread] 9 comments
1. iknows+(OP)[view] [source] 2023-05-24 17:28:39
Whats your point? You just ran a bunch of untrusted code when you visitied this website.
replies(2): >>EvanAn+o3 >>parl_m+zD
2. EvanAn+o3[view] [source] 2023-05-24 17:45:58
>>iknows+(OP)
Untrusted code running in a well-defined and maintained sandbox.
replies(2): >>pauldd+tl1 >>hardwa+rR1
3. parl_m+zD[view] [source] 2023-05-24 21:07:05
>>iknows+(OP)
Running a native binary in an environment with a large attack space and user level permissions is not NEARLY the same as running javascript in a browser with all of its sandboxing, isolation, and controls. And you know it.
◧◩
4. pauldd+tl1[view] [source] [discussion] 2023-05-25 02:54:16
>>EvanAn+o3
Yes and....
replies(1): >>EvanAn+SM2
◧◩
5. hardwa+rR1[view] [source] [discussion] 2023-05-25 09:18:02
>>EvanAn+o3
Still stuff manages to escape constantly

You can find exploits on gh for older chromium versions easily

replies(1): >>EvanAn+xM2
◧◩◪
6. EvanAn+xM2[view] [source] [discussion] 2023-05-25 15:36:52
>>hardwa+rR1
Even so it's disingenuous to compare running native code in an OS w/o a capabilities model to running Javascript in a browser.
◧◩◪
7. EvanAn+SM2[view] [source] [discussion] 2023-05-25 15:38:24
>>pauldd+tl1
Visiting a website and running Javascript vs. running a native application aren't equivalent. Browser sandbox exploits are "a thing" but that doesn't make the situations the same.
replies(1): >>pauldd+H63
◧◩◪◨
8. pauldd+H63[view] [source] [discussion] 2023-05-25 17:13:17
>>EvanAn+SM2
Yes and WASM can be sandboxed just as easily as JavaScript.

There is nothing "magical" about web browsers in that regard.

replies(1): >>EvanAn+Ie3
◧◩◪◨⬒
9. EvanAn+Ie3[view] [source] [discussion] 2023-05-25 17:54:09
>>pauldd+H63
I don’t follow where you’re going.

I didn’t say there was anything “magical” about browsers. They have a sandbox for JavaScript, by default. Windows doesn’t have a sandbox for native apps, by default.

A parent poster seemed to be making a statement of equivalency between running a native application in Windows and running JavaScript in a browser. I don’t think they’re equivalent.

That’s what I’m saying.

replies(1): >>iknows+E84
◧◩◪◨⬒⬓
10. iknows+E84[view] [source] [discussion] 2023-05-25 22:40:15
>>EvanAn+Ie3
We are literally talking about an environment for running Win32 apps in a sandbox
[go to top]