1. 4
  1. 7

    The paradox of the sandbox:

    A “successful” sandbox is popular. Popularity brings more and varied toys. Full of all sorts of kids and full of all sorts of toys— some dangerous. Finally, the intent of a safe partitioned off space is subverted.

    1. 1

      Can’t wait for sandbox 2. That will solve everything. Well, until it gets bloated and we move to sandbox 3.

    2. 10

      What could go wrong?

      1. 5

        Non rhetorically, it’s supposed to have some “origin” policy, but if you read the JavaScript attack on OS X messages, it was because they used a webview without origin controls, granting it full access to the local system. If Apple had implemented webusb too…

        1. 7

          I think it’s safe to say browser security history has shown the same-origin policy isn’t fail-safe.

      2. 6

        Reilly Grant was talking about the possibility of doing this before he left VMware to help get around some of the issues with (“clientless”) remoting via the web browser - it was one of the pieces WSX was missing. It’s interesting but not surprising he’s continuing the work over at Google.

        I’m still not convinced that the web browser needs to be the one and only platform, but apparently everyone else is, so why not?

        1. 1

          plz no