logoalt Hacker News

userbinatoryesterday at 9:52 PM2 repliesview on HN

It's really not surprising that letting websites run arbitrary code on your machine, even in a sandbox, would lead to things like this.


Replies

sigmoid10yesterday at 10:04 PM

There's no such thing as a sandbox "on your machine" when you really think about it. The code still runs on the same hardware and there are tons of ways to fiddle with said hardware that could be exploited (like rowhammer). The only "real" sandbox is fully dedicated hardware down to bare metal with zero connections to sensitive systems.

matheusmoreirayesterday at 10:09 PM

And now that Google's web environment integrity is getting repackaged into captchas, it seems we won't even be able to try to block such things in the future...