Skip to content

Sandboxing / Executing of Untrusted Code #173

Answered by steinerkelvin
zicklag asked this question in Q&A
Discussion options

You must be logged in to vote

In my understanding, this is just a matter of instantiating a clean slate HVM runtime without any of the default IOs and just injecting the relevant rules for the script system making sure they guarantee the sandboxing. And... coming to trust that the VM does not have a remote-code-execution-like vulnerability. Formalizing the HVM would indeed be a very strong step towards the latter.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@zicklag
Comment options

Answer selected by zicklag
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants