Re: Electrolysis security
Rob Arnold <[email protected]>
| Newsgroups | gmane.comp.mozilla.devel.dom |
|---|---|
| Message-ID | <[email protected]> |
> > If we serialize all file I/O we will need to provide some sort of file ID > back to the content process; my point is that ID should be tied to the > content process and not brute-forceable. > If we go that route, then yes. Why not mimic what the OS does for file > descriptor numbers or process ids? OpenBSD is particularly paranoid and uses > a secure random number generator for its pids. > Kernel panic mid-draft - should have proofread more. Corrected text above. -Rob