Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The issue is that "imposing the sandbox" isn't simple.

Apple themselves have "imposed a sandbox" for Safari since the first version appeared on iOS. Still we had multiple exploits, even though they owned both sides of the code.

Now imagine a situation where you're building a sandbox and the sandboxed application is using every trick possible to try to get out.



> Now imagine a situation where you're building a sandbox and the sandboxed application is using every trick possible to try to get out.

This hellish hypothetical you pose already exists. It’s called macOS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: