logoalt Hacker News

kllrnohjlast Sunday at 7:48 PM1 replyview on HN

WASM sacrifices guest security & performance in order to provide mediocre host sandboxing, though. It might be a useful tradeoff sometimes, but proper process-based sandboxing is so much stronger and lets the guest also have full security & performance.


Replies

IshKebablast Sunday at 7:54 PM

How is process-based sandboxing stronger? Also the performance penalty is not only due to sandboxing (I doubt it's even mostly due to it). Likely more significant is the portability.

show 1 reply