This was always nonsense. It assumes that the eyes know what they're looking at. Most people don't know how to look at code and see attack paths.
4,714 karma · joined September 16, 2022
Rapid7 -> Dropbox -> Grapl -> Datadog
This was always nonsense. It assumes that the eyes know what they're looking at. Most people don't know how to look at code and see attack paths.
But the process is still more capable than the VM. The process can talk to other processes via IPC, for example.
That's why you don't go from "javascript -> computer is taken over", instead you go from "javascript -> renderer control -> computer is taken over".
They could have blocked network access and required that it use a tool. That would have made limiting and monitoring network access even easier.
In fact, I wonder if teaching it "this is a bypass" would help it to model when it's doing its job vs working around the job.
You can make your arguments about noscript if you'd like (I have a great respect for the project) but I think it was essentially irrelevant to user security at the time, real users were really harmed by malware that exploited Firefox, Java, and Flash, and Chrome killed every one of those attack paths in virtually no time at all.
Computers were far more dangerous before Chrome. You watch old TV shows and it's a joke that people would visit a site and get hacked - that's unrecognizable today, it simply doesn't happen. It used to, Chrome changed that.
Firefox took a long time to catch up and their CEO was utterly incompetent, which seriously harmed Mozilla.
Seriously, this was a huge thing in C and C++, where you had to know/remember/know to look up very specific error codes and conditions in an API and if you didn't then it was very much considered to be a skill issue. This was maybe 15 years ago.
Writing, definitely. Reading, maybe. Thinking is another thing. I can think about code in a lot of ways just by reading a description of the code, or knowing how I directed the code to be written, etc. I think people are thinking about the code differently.
It has absolutely paid off, there are many people not using tokio.
Ultimately I have stuck to the informal verification of defining my expectations and ensuring that tests cover them.