zlacker

[parent] [thread] 2 comments
1. lblume+(OP)[view] [source] 2025-06-05 20:42:23
The difference is that V8 is sandboxed.
replies(2): >>gmueck+a6 >>Groxx+va
2. gmueck+a6[view] [source] 2025-06-05 21:28:38
>>lblume+(OP)
I haven't seen a single widely used sandbox that has never leaked.
3. Groxx+va[view] [source] 2025-06-05 22:12:07
>>lblume+(OP)
then replace "v8" with "arbitrary binaries" because that's true too. embed a lisp and do whatever you like, for example. Golang, C, Rust, Dart, etc are all quite common too, and nobody would call C "sandboxed".

all self-modifying really prevents you from doing is stuff like dynamically changing your permissions. which is a broadly reasonable restriction because it'd complicate the approval UI (and the actual enforcement mechanisms) quite a bit further.

[go to top]