Hacker News new | past | comments | ask | show | jobs | submit login

I have been waiting for years for attacks that operate entirely within the sandbox and steal cookies from memory, for example. What is more valuable that your Google cookies in a modern browser session? Who cares about machine access?



I think we've seen it once so far, for a Flash exploit that didn't have a sandbox escape in Chrome.


PPAPI plugins are sandboxed. That's their major difference from NPAPI plugins. The API itself is otherwise extremely similar.


I think you may be confused about who you're replying to and what subject you're replying on.


And, upon looking at your profile, I'm putting my foot in my mouth. Like, the whole thing, heel and all. :)


Upon re-reading the thread, I think you're right. Sorry!


No worries. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: