I'm starting to wonder if social networking sites (@facebook, @Twitter) and search sites (@Google) of today are similar to web browser engines around 2003 (?) or so, around when use-after-free had just been demonstrated to be a reliable security exploit.
If you work at a social media platform and you're not spending most of your day agitating for internal reform—on so many fronts—what are you doing?
Mar 19, 2018 · 8:56 PM UTC
1
1
5
Around this time, I think Microsoft stopped feature development for an extended period of time and focus on software security across Windows and Internet Explorer. This made a big difference to security. (It may have had interesting effects on the progress of Web technology.)
1
1
And to be clear: norms in the browser engine world are moving towards multiple layers of protection: writing code in safer languages, aggressively fixing even potential vulnerabilities, tools for software auditing, sandboxing that prevents many APIs from being called, etc.
1
1
2
