[WEB SECURITY] On sandboxes, and why you should care

Brian Eaton eaton.lists at gmail.com
Fri Mar 31 10:43:33 EST 2006

Someone (sorry, I've lost the original note) brought up the idea that
sandboxes provide good security value in a shared hosting environment.

Any views on how much security value is really there?  Are there a lot
of environments where some senstive application A is sharing a host or
an application server with a less secure application B?  And does
sandboxing application B do much to mitigate the threat of a
vulnerability in B being used to steal data from A?


