Linked by Thom Holwerda on Sun 10th Jun 2012 22:36 UTC
Thread beginning with comment 521693
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
Features
Linked by Thom Holwerda on 05/21/13 21:38 UTC
Linked by Thom Holwerda on 05/20/13 11:29 UTC
Linked by Thom Holwerda on 05/18/13 21:33 UTC
Linked by David Adams on 05/16/13 4:23 UTC
Linked by Thom Holwerda on 05/11/13 21:41 UTC
Linked by Thom Holwerda on 05/08/13 14:22 UTC
Linked by Thom Holwerda on 05/02/13 15:28 UTC
Linked by Thom Holwerda on 04/29/13 21:06 UTC
Linked by Thom Holwerda on 04/24/13 22:24 UTC
Linked by Thom Holwerda on 04/18/13 11:21 UTC
More Features »
Sponsored Links



Member since:
2011-01-28
Laurence,
"Metadata can be faked. This method ensures that only people tech-savy enough to know how not to break their browser has enough control to break their browser."
Can be faked to do what? Any metadata can be faked. But if the requested permissions are enforced by the sandbox and software attempts to escalate it's access above that specified in metadata, then it should be killed automatically. Furthermore the default max permissions should be restrictive enough such that the user needs to explicitly ok dangerous calls before the software will run.
The sandbox gives us much more security than we normally have when running extensions under blind faith. Although this could improve security for all extensions, I'd be open to removing sandbox restrictions from extensions that have already been vetted by google.