Secure EcmaScript, a runtime for running third-party code safely
github.com
github.com
Also note the experience of Figma who used the realms shim I think this project is using to secure Figma's JS based plug-ins system, only to promptly take a different approach when compromises were identified:
https://www.figma.com/blog/how-we-built-the-figma-plugin-sys...
https://www.figma.com/blog/an-update-on-plugin-security/
I am looking forward to Realms. Until then, I am doubtful of attempts to fully secure third party JS execution in the browser's engine.
That's a fairly good indictment of browser sandboxing :)
I'd probably stick to a WASM VM unless JS exposed the ability to spin up a separate VM like that on its own (which is very unlikely to ever happen).
This version removed direct access "Date" [2] but I'm not sure I'd trust any code running in the same process space given how hard it is to fix spectre in general.
[1] https://github.com/google/caja/wiki/SES#current-date-and-tim...
[2] https://github.com/Agoric/SES/tree/master/demo#taming-dateno...
Can someone ELI5 how a separate process would fix Spectre/Meltdown?
Meltdown is similar, but because a CPU affected by Meltdown does not perform permission checks during speculative execution, you can read memory that the execution environment doesn't even have permissions for. E.g. kernel memory.
The fix for Spectre is thus to only consider address spaces a security boundary; interpreters or JITs cannot be considerd security boundaries any more (in general).
> SES is not a security model or a security policy. SES is a way to build these using standard JavaScript. By taking this more general approach, SES allows each host to define its own approach to security (including the option to have no restrictions at all). This is important because a security policy that makes sense for scripts running on a lightbulb is unlikely to apply equally well to scripts running on a web server or scripts in a web page. SES provides tools in the language to build secure systems, but it is not a security system.
https://github.com/maple3142/wasm-jseval
I've been playing with this, exploring its potential for running user scripts.
As noted in another comment, Figma used a Realms polyfill for their plugins, similar to SES, then migrated to using WASM-ized QuickJS as a safer sandbox.