https://plus.google.com/u/0/+JustinSchuh/posts/CNEgtJWYTb5
http://lcamtuf.blogspot.com/2010/05/vulnerability-databases-...
Why? Surely as with any software one should only install extensions that one trusts?
https://seclab.stanford.edu/websec/chromium/chromium-securit...
When it's ready, hopefully Servo will be used as the basis for a browser that can provide security comparable to Chrome. But there's much more to that comprehensive goal than just writing a renderer in Rust.
Which is why the latest Servo builds have very strict sandboxing. People assume that Servo's security story is "just write it in Rust and it'll magically be secure". In reality, nobody on the team is that naive. The goal is to create a browser engine that achieves and significantly exceeds the state of the art. The architecture for that exists right now.
Neat that they have a sandbox up and running, though. I wasn't aware of that. Is there a paper somewhere I can read about their sandbox architecture?