Showing posts with label Sandboxing. Show all posts
Showing posts with label Sandboxing. Show all posts

Friday, 26 October 2012

Windows 8 Sandboxing - some links

I've always been a big fan of Application sandboxing because I really believe that is one of the best way to enforce application security (and to create an ecosystem that rewards secure coding and secure applications). As you can see on Past research on Sandboxing and Code Access Security (CAS)  I have done quite a lot of thinking and research about it ... until I gave up because nobody really cared (and FullTrust .Net apps are still the norm).

Now Microsoft seems to be re-inventing the Sanboxing model (again) and giving it another go with Windows 8 RT (RT = RunTime).

I don't know a lot about how it all works, but here are some quick links about it that I found:

At quick glance I haven't see a lot about policy's or permission's management/visualisation/code-analysis (am I missing it?)

Sunday, 16 August 2009

Past research on Sandboxing and Code Access Security (CAS)

Following a recent Twitter (@DinisCruz) thread, I realized that I had no post with links to my (failed) attempts to get Microsoft (and Sun) to allocate serious resources into Sandboxing of managed applications, and (specifically to .NET) into making Code Access Security work in the real world (i.e. figuring out what are the people, process and technologies required, so that it is possible to 'developt & deploy commercial applications & websites that run under a meaningful + effective Partial Trust environment').

If you are interrested in this topic, the best place to start is this PPT presentation (which was the last one I created): Making the case for Sandbox v1.1 - Dinis Cruz - SD Conference.ppt