Hacker News new | ask | show | jobs
by c4m 1663 days ago
That's right, it's essentially sandboxing the scripts. But I think the real innovation is an automated system they've created for writing the sandboxing code based on tracing the execution of the malicious/ad scripts in the browser.

Otherwise, what you're saying would be true, and this could be easy to break/bypass.

They discuss the details of this in the paper: https://brave.com/wp-content/uploads/2021/06/sugarcoat-ccs-2...