TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google App Engine Java security sandbox bypasses

92 点作者 tshtf超过 10 年前

5 条评论

_wmd超过 10 年前
It a pretty fair assumption to expect the Java runtime itself to be in an OS-level sandbox, Google would never treat that much native code as the last layer of security.<p>The App Engine CPython runtime can also be subverted in a variety of ways, but about the most exciting thing you can trigger here is for the process hosting your code to immediately be killed.
julianpye超过 10 年前
Google have a very good track record in security and that&#x27;s the reason why GAE-J is my system of choice. I am ignorant on their bounty offerings though, but I would have assumed Google are state of the art there. Can someone fill me in on the background and intentions of Security Explorations?
评论 #8710638 未加载
sauere超过 10 年前
Just JVM things.
xxxyy超过 10 年前
Can somebody explain me why GAE does not use virtualization as a security layer? Xen is a powerful, free, mature product that utilizes clever techniques along with hardware support to provide the best isolation layer yet available. AWS EC2 runs just fine on Xen, GAE seems to have lots and lots of hiccups.
评论 #8710403 未加载
评论 #8710383 未加载
评论 #8712053 未加载
评论 #8710391 未加载
评论 #8710454 未加载
arca_vorago超过 10 年前
Keep in mind that Oracle is one of the companies actively working with NSA as per some of the Snowden leaks. I trust anything java based not at all. (on the more practical side)
评论 #8709912 未加载