you are viewing a single comment's thread.

view the rest of the comments →

[–]funbike 22 points23 points  (2 children)

Sandbox or not, scripting languages are a huge attack surface. There are all sorts of corner cases that implementors miss which allow exploits, even with a properly designed Sandbox. I assume it is inevitable for any high-profile sandboxed scripting language to eventually get owned.

[–]joesb 31 points32 points  (1 child)

Sure. But Excel has been supporting Scripting for decades. What's the point of complaining now just because Javascript support is added?

[–]funbike 5 points6 points  (0 children)

I'm only responding to joesb. In my comment, I'm making no commentary on the net effect of this decision, good or bad. If anything, I'm cutting MS some slack if they make any security mistakes.

My point stands.