Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reducing the resolution coming from system timing sources is not going to stop attacks which have potentially infinite execution timelines.

Limiting JS execution resources, and in particular CPU cycles, will actually stop instead a whole swath of timing and resource-dependent attacks.

Please put your thought and chime into this thread:

https://bugzilla.mozilla.org/show_bug.cgi?id=1414675

Allowing infinite resources for remote programs is something we don't even do for local programs. Giving a ceiling to the JS runtime is a sound reasoning.

Please comment on the bug tracker!



Commenting on the upstream bug tracker would do so much more than lazily clicking upvote.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: