Long Live Sandboxing
noncombatant.org
noncombatant.org
Of course the approach is not a catch-all. A web browser that cares about performance isn't going to want to spawn a process for every bit of JSON it wants to parse, etc. Spectre has made this even worse, since now isolates/VMs are no longer considered boundaries - now every single site has to be isolated from every other (as is addressed in Chris's talk), or you need some sort of heuristic, or whatever.
There's also a massive gap between basic sandboxing and what Chrome does. Seccomp is very hard to maintain, but broader sandboxing like Windows Integrity or DAC on Linux, Apparmor, etc, are quite simple both to implement and to maintain.
What's notable about the ITW attacks is really just that
a) Chrome really owns the market now, and attackers know it's worth the time to exploit
b) Attackers have likely incorporated enough research and tooling to more cost effectively find vulnerabilities in Chrome
c) As the article points out, a lack of memory safety is extremely costly to try to make up for using just one other approach, even a great approach like sandboxing.
From the OS, which provides the sandboxing primitives, up to the broker, and into the renderer, we have memory unsafe languages. Shocker that sandbox escapes occur.
Sucks that Google is so invested in C++, it's obvious that organizational inertia has kept Rust out of Chrome.
(Since their new exploits tend to be in big new APIs that relate to new flags, I think they would be well served by using rust for this splattering of new apis.)
It's exactly the sort of thing this post is talking about. I'm not advocating for a wholesale rewrite, that would be ridiculous - but there's very obviously certain areas of attack surface that are harder to sandbox and are great candidates.
Besides, Firefox is even older than Chrome, and at least as complex, and they began the process of replacing core attack surface. Google could put 10x the devs on such a thing.
Except they’ve repeatedly ignored previous efforts to upstream sandboxing for FreeBSD.
Which platforms?