Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <7758b7f4-a71a-48a6-b4a9-516700650a7e@free.fr>
Date: Wed, 20 May 2026 21:18:43 +0200
From: Gabriel Corona <gabriel.corona@...e.fr>
To: oss-security@...ts.openwall.com
Subject: Re: On the issue of MIME handlers that execute
 arbitrary code (e.g. Wine)

> Sandboxes should only allow allowlist of file types and make everything
> else fall back to a safe default.  This could be a simple text editor
> (no IDE support!) for text files, and a hex editor (or an error) for
> binary files.

That sounds extremely inconvenient. Running an email client in a 
sandbox? It can't open a PDF or a JPEG (or worse, you'll get an 
hex-editor) ...

If the sandboxed application is badly integrated and can't open files 
and URIs, the user (me included) will prefer using the non-sandboxed 
version in order to get things done (or will prefer using a more 
user-friendly OS). This would defeat the purpose of having sandboxed 
applications.

Gabriel

Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (841 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.