zlacker

[parent] [thread] 1 comments
1. Philip+(OP)[view] [source] 2023-07-26 13:43:50
One thing about this that I don't understand is how they intend to validate memory without controlling the entire stack (which we aren't even 1% close to achieving on the desktop). If I poke /dev/mem, does that mean Chrome will have to validate every single byte of it's ram? Or does it rely on having a fully locked down environment (maybe feasible on phones).
replies(1): >>TillE+Y2
2. TillE+Y2[view] [source] 2023-07-26 13:55:11
>>Philip+(OP)
Even on Windows, you can do practically anything with a signed driver.

There's just no such thing as verifying a "secure environment" outside of extremely narrow, controlled scenarios.

[go to top]