Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But you'd also have to have an entire VM to run the separate process in, otherwise it still has access to the user's whole account and desktop.

(unless UWP I suppose, which even Microsoft have kind of forgotten about)



Sandboxing APIs exist for a reason.


Which APIs guarantee non-escape of native code?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: