HNHacker News
TopNewBestAskShowJobs

grun

770 karma · joined September 28, 2011

submissionscomments
grun··on Show HN: Virtual Machines in the Browser
An attacker would have three primary avenues of attack:

  1) Escape the virtual machine sandbox.
  2) Denial of service of host resources.
  3) Attack network services.
For 1), virtual machines provide strong, hardware supported isolation of the host. They can't access the filesystem, resources, or hardware of the host, only their own.

For 2), virtual machines also provide strong protection from the denial of service of host resources. Virtual machines can be restricted in memory, CPU, and device use while running. This occurs routinely with virtual machines provisioned on servers.

Network services, 3), are the largest attack vector not protected by encapsulation within a virtual machine. One weapon virtual machines do posses, however, is complete control over the virtual NIC. Every packet sent or received can be inspected, modified, or discarded.

Arc's network policy is not carved in stone. There is nothing preventing Arc from adopting a same-origin policy, like browsers. Perhaps it will.

grun··on Show HN: Virtual Machines in the Browser
> what happens when you try to run more VMs than you have physical cores?

The VMs are just processes of the host OS. They're multiplexed over available cores, same as ordinary processes.

grun··on Show HN: Virtual Machines in the Browser
Dirpy had three million monthly users.
grun··on Show HN: Virtual Machines in the Browser
Arc apps will require explicit permission to communicate with a local network. This can be enforced at the hardware layer by the virtual NIC.
grun··on Show HN: Virtual Machines in the Browser
Please shoot me an email so I can destroy the bug.
grun··on Show HN: Virtual Machines in the Browser
VirtualBox is included in the Arc installer. It doesn't have to be downloaded or installed separately.
grun··on Show HN: Virtual Machines in the Browser
Arc is an indomitable name. It's short, memorable, recognizable, and pronounceable. It's also a strong prefix: Arc app, Arc box, Arc sync, Arc OS, etc.

Arc passes the highway test with flying colors. Imagine driving down the highway when an 18-wheeler thunders past. If you remember the name stamped on the side of the corrugated shipping crate, it's a good name. 'Arc' in a Neo-grotesque typeface next to an iconic logo on such a shipping crate is as good as burning Arc into your retina with a megawatt laser.

grun··on Show HN: Virtual Machines in the Browser
Dirpy had three million monthly users.
grun··on Show HN: Virtual Machines in the Browser
> How does one try out this beta?

Documentation for Arc and arc.js will be available shortly.

> Is this going to be open source?

Arc will not be.

Perhaps Peggo once Arc has cooled.

grun··on Show HN: Virtual Machines in the Browser
> If I have a VM in the browser can I run.. vim in the browser? My customized instance and all that? Or maybe this wouldn't be too feasible for io-heavy uses?

vim, emacs, anything that runs on Linux.

grun··on Show HN: Virtual Machines in the Browser
Native Client

  1) Is Chrome only.
  2) Can't spawn processes or subprocesses.
  3) Can't open raw UDP or TCP sockets.
  4) Requires apps be ported.
grun··on Show HN: Virtual Machines in the Browser
> Would the difference here be that instead of running Java, you could run > almost any language?

More than just any language - any Linux software.

grun··on Show HN: Virtual Machines in the Browser
> From an end-user POV, what will using an Arc app entail?

If Arc is installed, you're good to go. Everything just works. If Arc isn't installed

  1) arc.js transparently falls back to the cloud and runs the Arc app on a
     server. The user doesn't know the difference.
and/or

  2) Upsell the user to install Arc.
I haven't built the transparent cloud fallback yet.

> What is to prevent other websites from being malicious and connecting to your > locally-installed Peggo VM and trashing it or otherwise exploiting it?

The web server running in the Arc app can check the Referer header to verify the request came from a permissible domain.

grun··on Python URL manipulation made simple.
Query parameters as a dictionary was an ease of use tradeoff over the rarely utilized flexibility of repeated query parameters.

  https://github.com/gruns/furl/blob/master/furl.py#L142
Werkzeug's MultiDict looks like a good combination for the best of both worlds, ease of use and flexibility. Thanks for the reference.
grun··on Python URL manipulation made simple.
No restrictions. Use however you deem fit.
← PreviousPage 3 of 3