Wait, does the platform not include a sandbox to make sure this doesn't happen? What "security" can you expect to get out of such a platform?
Wait, does the platform not include a sandbox to make sure this doesn't happen? What "security" can you expect to get out of such a platform?
Third parties could figure out that private API and call it themselves.
I do not think it is practical to defend the system against thos. Moving that base class into the kernel takes performance and includes its own security risks. Shipping multiple versions of the OS with different layouts or even implementations for such subclasses might help a bit, but also would open the system for bugs that show up on only 1/N of the machines.
http://msdn.microsoft.com/en-us/library/windows/apps/hh46504...
They could use NaCl [1] or develop a similar SFI technology just for Windows.
http://daringfireball.net/2008/11/google_mobile_uses_private...
(Disclaimer: I work for Microsoft, though not on Windows.)