What's the security like on Steam workshop? Or Nexusmods? Gaming and modding is still rife with lots of little "here download my exe from this forum post and give it a run please".
Pretty much every game I play modded ends up with some kind of support framework DLL that tons of other mods build from. I am amazed that that has still not really blown up in our faces here in 2023.
Which is especially surprising considering the sheer insanity of Minecraft modders and hackers.
There's a lot of hinky stuff out there that doesn't quite reach the level of "malware", just potential fun.
specialized "Visual Studio" extensions are worth looking hard at too.
Sandboxing Java code running in process requires ugly and obscure security APIs and restricts you to having to have a common modding API (Forge). Many mods use bytecode patching and would be broken completely.
Granted, this is a large concern for clients.
People thought of sandboxing the stuff, but the people thinking of that and the people making the mods aren't the same people and the people making the mods would rather be able to do things outside a single API.
Many mods though, work by just subverting the game by replacing components with custom-made ones. This allows substantially more customization.
In Minecraft, both types exist. The first type are called "data packs" or "resource packs" and would not be subject to this attack. The latter type involves swapping in new .jar files and running them directly, which is unsupported by the developer and gives basically unrestricted access.
If so how is it really any different from just regular nodejs packages or Python packages?that’s a risk developers seem to ignore.
Or are your talking about scripts being added for modding purposes like Minecraft? If so that’s a pretty good point, would be nice to have godot implement some sort of sandboxed system you can use. Not sure what the term would be or how that would even work.
A sane system should not be compromised no matter where the executable is from.
So, you're saying a sane system should not run arbitrary code I tell it to run? Which is different from iOS security model how?
(If not, please explain how your hypothetical magic OS resists compromise without limiting instructions it would execute)
Security is upheld, user control is given, everyone is happy.
Not having admin rights is almost uselessly crude as a “sandbox”.
More recently, I've been following https://github.com/microsoft/win32-app-isolation which seems incredibly interesting! If they can pull it off, we will have mobile-os like security on windows, finally, after all these years.
It has been my #1 feature request for windows for so long... I almost can't believe it's actually happening.