Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Without commenting on v8 isolates specifically, this doesn't necessarily hold in any isolation situation; many customers are running code on behalf of their customers, which are often submitting jobs on behalf of theirs, and so on. Isolation breaches within a platform customer can result in significant cross-user data breaches.
 help



You're right, but there are cases when the risk can be managed. Like if you're running an auth lambda in one isolate, and another isolate is running the exact same copy of the code, I'd say malicious exploitation would be low enough a risk, that I'd be comfortable running things like this.

And I'd say this even is a majority use case.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: