Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

Off-topic discussion/chat/argue area with special rules of engagement.
Forum rules
The Off-Topic area is a general community discussion and chat area with special rules of engagement.

Enter, read and post at your own risk. You have been warned!
While our staff will try to guide the herd into sensible directions, this board is a mostly unrestricted zone where almost anything can be discussed, including matters not directly related to the project, technology or similar adjacent topics.

We do, however, require that you:
  • Do not post anything pornographic.
  • Do not post hate speech in the traditional sense of the term.
  • Do not post content that is illegal (including links to protected software, cracks, etc.)
  • Do not post commercial advertisements, SEO links or SPAM posts.
We also ask that you keep strongly polarizing topics like politics and religion to a minimum. This forum is not the right place to discuss such things.
Please do exercise some common sense. How you act here will inevitably influence how you are treated elsewhere.
User avatar
suzyne
Astronaut
Astronaut
Posts: 736
Joined: 2023-06-28, 22:43
Location: Australia

Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

Unread post by suzyne » 2024-04-09, 22:43

I understood less than 50% of this article, but my take away is that the way Chrome works is a security nightmare?

https://thehackernews.com/2024/04/google-chrome-adds-v8-sandbox-new.html
Laptop 1: Windows 11 64-bit, i7 @ 2.80GHz, 16GB, NVIDIA GeForce MX450.
Laptop 2: Windows 10 32-bit, Atom Z3735F @ 1.33GHz, 2GB, Intel HD Graphics.
Laptop 3: Linux Mint 20.3 64-bit, i5 @ 2.5GHz, 8GB, Intel HD Graphics 620.

User avatar
moonbat
Knows the dark side
Knows the dark side
Posts: 5605
Joined: 2015-12-09, 15:45

Re: Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

Unread post by moonbat » 2024-04-09, 23:52

It anyway is a security nightmare thanks to their efforts to change a web browser from being primarily a document parser to a freaking virtual machine by importing several features that used to be left to the OS. Larger code base = larger attack surface.
"One hosts to look them up, one DNS to find them and in the darkness BIND them."

Image
KDE Neon on a Slimbook Excalibur (Ryzen 7 8845HS, 64 GB RAM)
AutoPageColor|PermissionsPlus|PMPlayer|Pure URL|RecordRewind|TextFX
Jabber: moonbat@hot-chili.net

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 37762
Joined: 2011-08-28, 17:27
Location: Motala, SE

Re: Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

Unread post by Moonchild » 2024-04-10, 08:18

So.. they are basically telling us that Chrome didn't have basic protections in place that we've had for many years?
XD
"A dead end street is a place to turn around and go into a new direction" - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
jobbautista9
Keeps coming back
Keeps coming back
Posts: 957
Joined: 2020-11-03, 06:47
Location: Philippines

Re: Google Chrome Adds V8 Sandbox - A New Defense Against Browser Attacks

Unread post by jobbautista9 » 2024-04-12, 04:11

Yeah wtf. I've read so many of Spidermonkey's source code than I wanted during my work on separating mozjs from monolithic xul, and I'm pretty sure I remember our SM already doing plenty of things mentioned in the article... :coffee:
Image

"Destroying things, smartly!" - IJN Samidare, probably

Avatar artwork by ebifurya: https://www.pixiv.net/artworks/85379109

XUL add-ons developer. You can find a list of add-ons I manage at http://rw.rs/~job/software.html.