Skip to main content

Showing 1–2 of 2 results for author: Garfinkel, T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2003.00572  [pdf, other

    cs.CR

    Retrofitting Fine Grain Isolation in the Firefox Renderer (Extended Version)

    Authors: Shravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd, Eric Rahm, Sorin Lerner, Hovav Shacham, Deian Stefan

    Abstract: Firefox and other major browsers rely on dozens of third-party libraries to render audio, video, images, and other content. These libraries are a frequent source of vulnerabilities. To mitigate this threat, we are migrating Firefox to an architecture that isolates these libraries in lightweight sandboxes, dramatically reducing the impact of a compromise. Retrofitting isolation can be labor-inten… ▽ More

    Submitted 9 March, 2020; v1 submitted 1 March, 2020; originally announced March 2020.

    Comments: Accepted at Usenix Security 2020

    MSC Class: D.4.6 ACM Class: D.4.6

  2. arXiv:1912.02285  [pdf

    cs.CR

    Gobi: WebAssembly as a Practical Path to Library Sandboxing

    Authors: Shravan Narayan, Tal Garfinkel, Sorin Lerner, Hovav Shacham, Deian Stefan

    Abstract: Software based fault isolation (SFI) is a powerful approach to reduce the impact of security vulnerabilities in large C/C++ applications like Firefox and Apache. Unfortunately, practical SFI tools have not been broadly available. Developing SFI toolchains are a significant engineering challenge. Only in recent years have browser vendors invested in building production quality SFI tools like Nati… ▽ More

    Submitted 4 December, 2019; originally announced December 2019.

    MSC Class: D.4.6 ACM Class: D.4.6