Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
comex
on Nov 25, 2016
|
parent
|
context
|
favorite
| on:
Why pledge(2) or, how I learned to love web applic...
Yes; I'm not too familiar with Windows but I know there's no syscall-by-syscall lockdown. However, they were able to disable all Win32k syscalls starting in Windows 8, which is a significant attack surface reduction compared to the past:
https://www.chromium.org/developers/design-documents/sandbox...
:
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
https://www.chromium.org/developers/design-documents/sandbox...: