Hacker News new | ask | show | jobs
by mst 1483 days ago
I think the idea is that the OS has a better chance of keeping the plugin isolated than a VM sandbox.

I'd certainly trust v8's sandboxing over any attempt to do it myself but OS level sandboxing + IPC seems like an even better idea if you're trying to be really sure.