youtube image
From YouTube: SES-mtg: Confining an iframe

Description

Recorded from the "SES Strategy" meeting on Jan 24, 2019.

Caja consisted of two main parts: Domado, for securing/virtualizing the browser APIs, and SES, for securing JavaScript. Securing the html4 browser API and ES3 were both horrendously difficult. Changes to JavaScript made securing it easy. Changes to the browser have only made the Domado problem worse. What could be changed about the browser to make Domado-level security easy?