Microsoft calls WebGL "harmful"
blogs.technet.com
blogs.technet.com
~ https://twitter.com/ID_AA_Carmack/statuses/81732190949486592
Any thoughts from someone who's more informed than me?
Carmack tweeted the same:
"doing GL ES from NaCL is clearly just as dangerous as WebGL"
http://twitter.com/#!/ID_AA_Carmack/status/81767700447236096
In theory, you could do software rendering in NaCl, but that wouldn't produce as good results as GPU, despite NaCl being more powerful than JavaScript (for example SwiftShader DirectX9 SW renderer scores 620 on 3DMark06 on pretty beefed up quadcore [1], my 2 year old notebook GPU scores over 4000).
So the question is not "is WebGL secure?", question is "are benefits of HW accelerated 3d on the web worth the risks?".
To which IMHO the answer is resounding yes. Problems are minor, benefits are major.
An interesting question would be "If all these security concerns were resolved, would Microsoft then implement WebGL?". Then, I guess, the answer is still no, because WebGL is based on OpenGL and not DirectX.
"If all these security concerns were resolved,
would Microsoft then implement WebGL?"
To me that's irrelevant - Chrome and Firefox combined have enough market share to make WebGL useful.What is important to me is if they are right, what are the Khronos Group doing about it? Is WebGL really designed for the web?
AND, can it be fixed without relying on companies fixing their drivers or is it a fundamental flaw?
I can't help but wonder. If those drivers are so buggy, why isn't this a high priority to fix? It would probably be easier for hackers to attack other things due to the wide range of drivers but if the security issues claims against WebGL are real then escalation of privileges on any OS is a question of breaking the GPU driver.
I find that to be a big issue even with WebGL not in the picture.
It will come. Raised concerns are not WebGL specific, WebGL is just exposing things about HW-accelerated 3d to more general public that have been here since always and every GPU 3d technology has to face (problems with drivers, fragmentation of market, very wide spread in capabilities).
People will need to get used to update their drivers (the same as they already got used to update their OS and browsers).
Gamers are already doing this since forever, not because of security concerns but for bugfixes / performance improvements.
GPU vendors are actually pretty responsive, I'm aware of driver hotfixes released just to address problems discovered on releases of particular games (in between regular monthly driver updates).
However, WebGL does make it worse: it trivially exposes local privilege escalations as remotely-exploitable root vulnerabilities. It also does so bypassing a lot of the sandboxing work that browser vendors have done to contain browser vulnerabilities.
Do they have a non-propriety alternative? The closest thing I can think of is WPF, which is based on Directx.
it's the exact feelings we had about XP security
Well, actually, Linux or OS X security isn't that much better for the end-user, unless you're a sysadmin with some experience and know how to configure stuff like IPTables and SELinux.Otherwise when navigating the web, security is as better as its weakest links - the user and its browser.
The sandboxing code would have to rely on the video drivers ("the OS running on the card") to similarly manage resources on a video card.
Problem with that is that the video card may not support some required functionality or that the driver may be buggy. Top of the line video hardware has a shelf life of say a year. That puts serious pressure on producing drivers fast. In addition, there is pressure to produce fast drivers, as that is what reviewers look at. You cannot get fast reliable drivers soon, so drivers will be buggy, incomplete, etc.
You cannot build reliable sandboxing on top of buggy drivers.