Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why throw WebAssembly into the mix, especially if you want to run this outside of the browser? What benefit do you see?


WebAssembly should be the world's most robust, well-tested sandboxing technology: it's been running in browsers for five years now, so it's been more extensively tested than anything else.

I want a sandbox that's robust, widely used and widely tested. WebAssembly feels like it should be the best possible option.

If you have a better idea for a sandbox I can use to run untrusted code on my laptop (and phone) I'd love to hear what it is!


Normal machine code runs in even more contexts and has been for much longer. I don't know any numbers on how many mainstream projects are WebAssembly but it feels like a stretch to call it the "worlds most robust and well-tested" anything. And the tech itself doesn't sandbox anything so it just feels like a strange choice.

Use KVM if you're on Linux/Android. It's not about the binaries but where and how it's running, there is 0 isolation in WASM alone, and creating a new runtime to run it outside of browsers will not give you what you're looking for.

Android recently announced they're going the KVM route.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: