Comment by dtf
7 hours ago
It's the "rule of two" safety guideline mentioned and linked to in the article:
https://chromium.googlesource.com/chromium/src/+/main/docs/s...
If you use a safe language like Rust, you can afford untrusted input and no sandboxing.
If you use an unsafe language such as C++, you must chose between trusted inputs or sandboxing.
I was curious as to where rfgplk's implementation lay within the Venn diagram.
What counts as two safety mechanisms?
> you can afford untrusted input and no sandboxing.
I would not trust a rust program un-sandboxed! There are security bugs in rust itself.