Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> all of which were designed back in the '90s, when we didn't appreciate just how dangerous an environment the Internet could become.

No, it was in the 2000's and 2010's. And even more than 10 years ago, people were aware of how Internet can be dangerous, as shown by Internet Explorer.

Moreover, Firefox had sandboxing before Chrom* and Electrolysis:

1. https://developer.mozilla.org/en-US/docs/Archive/Add-ons/Sec...

2. https://developer.mozilla.org/en-US/docs/Archive/Add-ons/Dis...

3. https://developer.mozilla.org/en-US/docs/Archive/Add-ons/Int...



The "sandboxing" you're referring to was very limited in scope. It essentially amounted to not giving content scripts any references to non-content objects like the browser chrome; poorly written extensions often broke this "sandbox", and it provided no protection whatsoever against browser exploits -- any arbitrary code execution exploit would allow an attacker to run unrestricted code on the user's system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: