logoalt Hacker News

dummydummy1234 • yesterday at 7:48 PM • 3 replies • view on HN

Why are v8 isolates bad, I see speculative execution hacks, but are there others?


Replies

phickey • yesterday at 7:58 PM

Despite naming them isolates, the V8 team does not consider them to be a security boundary.

vmg12 • yesterday at 8:38 PM

The v8 JIT is very complex and can lead to sandbox escapes if there are type confusion bugs.

binsquare • yesterday at 7:56 PM

v8 isolates are still shared kernel

while microvm's are separate kernel + hardware virtualization through hypervisor guarantees

I wouldn't call it bad either, just different tools for different things

➕ show 1 reply