I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit
blog.polybdenum.com
blog.polybdenum.com
Code Access Security has been removed from the .NET framework [1]. And Java's SecurityManager is deprecated for removal in future versions of Java [2].
[1] https://docs.microsoft.com/en-us/dotnet/framework/misc/code-...
The downside is they are more memory hungry.
Javascript and webassembly still aim for for in process sandboxing, though browsers add process level security as defense-in-depth.
The reason this is now being considered for removal is that even though this mechanism is very flexible and powerful in theory, it is too elaborate to be used correctly by most programmers in practice.
I can see how careless use of it can lead to an unintentionally rather massive security surface area though...
There was a lot of interest in early days of Java and the internet in mobile code that could move between devices. It seems that interest in such systems has waned. I suppose this was more of a solution looking for a problem. However, I still think that there is potential there in some way.
Meanwhile the first security papers already started being shown.
When IBM developed Websphere for the 1996 Atlanta Olympics, they wanted a mainframe, but you know, web stuff. The model was doomed from the start, as they designed the JVM to run as a process.
Sun attempted tried to get deeper kernel support for the JVM with Solaris, but ultimately just ended up developing the precursor to LXC Containers called Solaris Zones.
What we have today with containers is pretty awesome but it was definitely a bumpy road to figure it all out.
The JAAS idea was quite good, however it was too complex for most developers to implement properly.
I see a big failure for .NET and Java not having been a JIT/AOT stack since the beginning, and now we are going through their reboots while trying to keep the existing ecosystems to fall apart in the process.
I think Android has done a very good job with their permissions, which seem quite similar to me. Am I missing something?
Yes, properly limiting permissions is difficult, and there can be bugs, but that's true regardless of what layer the security controls are applied at.
> Yes, properly limiting permissions is difficult, and there can be bugs, but that's true regardless of what layer the security controls are applied at.
Also despite being based on Linux kernel, since Project Treble Android has doubled down on its Binder mechanism for IPC across drivers, kernel and activities with multiple processes, which in the end makes it look like microkernel based architecture.
https://gitlab.ow2.org/asm/asm/-/issues/316506
12 October 2013: ASM 4.2 (tag ASM_4_2) 316506 ByteVector doesn't validate byteLength in putUTF8().
https://asm.ow2.io/versions.html
Couldn't find a CVE
[1] https://cloud.google.com/blog/products/containers-kubernetes/how-gvisor-protects-google-cloud-services-from-cve-2020-14386
[2] https://cloud.google.com/appengine/docs/standard/runtimesFlex really is for the edge cases where you need really big instances or really long execution times.
(I used to work at GCP)