Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah no disagreement there. I had totally forgotten about the JS POC - ugh!

The JavaScript argument is interesting to me in that it's already flawed. I suppose I'd rather focus on the security issues with browsers running code on my computer more than anything else since it's effectively the "but what about ___" answer to so many threads like this one.

I've seen a few other comments suggesting per-process rules to enable or disable branch protections. That's an interesting thought, especially considering you could apply it to either "trusted" or "untrusted" code depending on it's source.



With Arm big.little architectures, it could start making sense to have dedicated in-order cores for running JavaScript and other “untrusted” code.

Also, I wonder if disabling mitigations on the desktop and running the browser in a VM with mitigations enabled would be effective.


People want their websites to load fast, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: