Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With so many escape issues the term sandboxed browser is a little more than a marketing phrase

https://github.com/allpaca/chrome-sbx-db

Rest easy



Nice list. Now you need a RCE exploit and a chained breakout exploit thought. That's a lot of cash.

Given this and that the process isolation also protects against meltdown/spectre type attacks, I think we can agree that this type of fine-grained sandboxing is a requirement for secure software, no?

However, next to no software is using fine-grained sandboxing. From the top of my head only qmail, djbdns and gatling come to mind, none of them are for end-users.

So what end-users software does actually approach or surpas browsers in this regard?


Then lets not pretend that a browser is sufficiently secure for people considering using OpenBSD. Given the fact that by its nature a browser runs untrusted unreviwed code on your device it does a pretty good job of making it difficult to exploit, but it is irresponsible to say that its sandboxing cant be bypassed when clearly it can.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: