{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T05:06:33Z","timestamp":1750309593575,"version":"3.41.0"},"reference-count":18,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,5,8]],"date-time":"2025-05-08T00:00:00Z","timestamp":1746662400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2025,5,8]]},"abstract":"<jats:p>Sandboxing mitigates the risks of software so large and complex that it's likely to harbor security vulnerabilities. To safely harness useful yet ominously opaque libraries, a simple mechanism provides ironclad confinement\u2014or does it?<\/jats:p>","DOI":"10.1145\/3733699","type":"journal-article","created":{"date-parts":[[2025,5,15]],"date-time":"2025-05-15T16:18:18Z","timestamp":1747325898000},"page":"18-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Sandboxing: Foolproof Boundaries vs. Unbounded Foolishness"],"prefix":"10.1145","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-1607-5674","authenticated-orcid":false,"given":"Terence","family":"Kelly","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Edison","family":"Fuh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,5,15]]},"reference":[{"volume-title":"You Can't Win","author":"Black J.","key":"e_1_2_1_1_1","unstructured":"Black, J. 1926. You Can't Win. MacMillan; https:\/\/gutenberg.org\/ebooks\/69404.txt.utf-8."},{"key":"e_1_2_1_2_1","volume-title":"Exploit programming: from buffer overflows to weird machines and theory of computation. Usenix ;login: 36(6)","author":"Bratus S.","year":"2011","unstructured":"Bratus, S., Locasto, M. E., Patterson, M. L., Sassaman, L., Shubina, A. 2011. Exploit programming: from buffer overflows to weird machines and theory of computation. Usenix ;login: 36(6); https:\/\/www.usenix.org\/publications\/login\/december-2011-volume-36-number-6\/exploit-programming-buffer-overflows-weird."},{"key":"e_1_2_1_3_1","volume-title":"Vulnerability: Double free bug in zlib compression library corrupts malloc's internal data structures","author":"CERT.","year":"2002","unstructured":"CERT. 2002. Vulnerability: Double free bug in zlib compression library corrupts malloc's internal data structures; https:\/\/kb.cert.org\/vuls\/id\/368819."},{"key":"e_1_2_1_4_1","unstructured":"Constructors of confusion in C++ 2025. Read a few of the FAQs that start at https:\/\/isocpp.org\/wiki\/faq\/ctors#static-init-order-on-first-use and you'll see this is a mess."},{"key":"e_1_2_1_5_1","article-title":"Weird machines, exploitability, and provable unexploitability","author":"Dullien T.","year":"2020","unstructured":"Dullien, T. 2020. Weird machines, exploitability, and provable unexploitability. IEEE Transactions on Emerging Topics in Computing 8(2); https:\/\/ieeexplore.ieee.org\/document\/8226852.","journal-title":"IEEE Transactions on Emerging Topics in Computing 8(2); https:\/\/ieeexplore.ieee.org\/document\/8226852."},{"volume-title":"Practical Cryptography","author":"Ferguson N.","key":"e_1_2_1_6_1","unstructured":"Ferguson, N., Schneier, B. 2003. Practical Cryptography. Wiley. See Section 1.2, \"The Evils of Features.\""},{"volume-title":"Why bloat is still software's biggest vulnerability","author":"Hubert B.","key":"e_1_2_1_7_1","unstructured":"Hubert, B. 2024. Why bloat is still software's biggest vulnerability. IEEE Spectrum 61(4). Paywall: https:\/\/ieeexplore.ieee.org\/document\/10491389. Possibly without paywall: https:\/\/spectrum.ieee.org\/lean-software-development."},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Kamp P.-H. 2014. Please put OpenSSL out of its misery. acmqueue 12(3). https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2602649.2602816.","DOI":"10.1145\/2602649.2602816"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Kelly T. 2024. Zero tolerance for bias. acmqueue 22(2); https:\/\/queue.acm.org\/detail.cfm?id=3664645.","DOI":"10.1145\/3664645"},{"key":"e_1_2_1_10_1","first-page":"70","volume-title":"UNIX: A History and a Memoir","author":"Kernighan B.","year":"2020","unstructured":"Kernighan, B. 2020. UNIX: A History and a Memoir. Kindle Direct Publishing. See pp. 67?70 for pipes and filters."},{"key":"e_1_2_1_11_1","unstructured":"Linux man pages. https:\/\/man7.org\/linux\/man-pages\/: clock_gettime(2) close(2) dup2(2) environ(7) execve(2) fork(2) gcc(1) ld(1) ld.so(8) mkstemp(3) pipe(2) poll(2) prctl(2) read(2) setrlimit(2) syscall(2) vdso(7) wait(2) write(2)."},{"key":"e_1_2_1_12_1","unstructured":"Miller M. S. Yee K.-P. Shapiro J. 2003. Capability myths demolished. Technical Report SRL2003-02 Johns Hopkins University Systems Research Laboratory; https:\/\/papers.agoric.com\/assets\/pdf\/papers\/capability-myths-demolished.pdf."},{"key":"e_1_2_1_13_1","volume-title":"TEMPEST: A signal problem","author":"National Security Agency.","year":"2013","unstructured":"National Security Agency. TEMPEST: A signal problem; https:\/\/web.archive.org\/web\/20130918021523\/http:\/www.nsa.gov\/public_info\/_files\/cryptologic_spectrum\/tempest.pdf."},{"volume-title":"Preventing privilege escalation. Proceedings of the 12th Usenix Security Symposium","author":"Provos N.","key":"e_1_2_1_14_1","unstructured":"Provos, N., Friedl, M., Honeyman, P. 2003. Preventing privilege escalation. Proceedings of the 12th Usenix Security Symposium; http:\/\/www.usenix.org\/events\/sec03\/tech\/full_papers\/provos_et_al\/provos_et_al.pdf. See p. 239 for a zlib bug that created a remote root exploit vulnerability in sshd more than 20 years before the recent ssh\/xz affair."},{"volume-title":"The Art of UNIX Programming","author":"Raymond E. S.","key":"e_1_2_1_15_1","unstructured":"Raymond, E. S. 2004. The Art of UNIX Programming. Addison-Wesley. See p. 266 for the filter pattern."},{"key":"e_1_2_1_16_1","first-page":"552","volume-title":"Advanced Programming in the UNIX Environment","author":"Stevens W. R.","unstructured":"Stevens, W. R., Rago, S. A. 2013. Advanced Programming in the UNIX Environment, third edition. Addison-Wesley. See pp. 548?552 for coprocesses."},{"key":"e_1_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Thompson K. 1984. Reflections on trusting trust [Turing Award lecture]. Communications of the ACM 27(8); https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/358198.358210.","DOI":"10.1145\/358198.358210"},{"key":"e_1_2_1_18_1","unstructured":"Zlib. January 2024; https:\/\/www.zlib.net\/."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733699","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733699","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:56:56Z","timestamp":1750298216000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733699"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,8]]},"references-count":18,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,5,8]]}},"alternative-id":["10.1145\/3733699"],"URL":"https:\/\/doi.org\/10.1145\/3733699","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2025,5,8]]},"assertion":[{"value":"2025-05-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}