Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Astra for Law(openai.com ↗)
    361comments
  2. Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint(prismml.com ↗)
    75comments
  3. Goose: 1.16x faster than C++ and 1.12x than safe Rust, while memory safe(github.com/aardappel ↗)
    26comments
  4. Bend – A language that blocks AI mistakes via proof, on CPU and GPU(bend-lang.com ↗)
    155comments
  5. Hister: A private search engine for the pages you visit and the files you keep(github.com/asciimoo ↗)
    137comments
  6. Wax motor(wikipedia.org ↗)
    50comments
  7. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    198comments
  8. Alibaba releases Qwen 3.8 Omni Flash(qwen.ai ↗)
    5comments
  9. Telstra outage: The night a network decided the year was 2006(netnod.se ↗)
    2comments
  10. Flet 1.0 – Build cross-platform apps in Python(flet.dev ↗)
    34comments
  11. Diplodocus, Long Thought Exclusively American, Turns Up in Spain(sci.news ↗)
    20comments
  12. More than 100k people in Japan are now aged 100 or older(bbc.com ↗)
    123comments
  13. I Put Nam A2-Lite Inside an iRig HD X(playtaurus.com ↗)
    1comments
  14. CrowdSec Source Code Leak(crowdsec.net ↗)
    40comments
  15. Infinite-Parameter LLMs: Generating and Adapting Weights from Live Data(arxiv.org ↗)
    34comments
  16. How Uber Protects Against Retry Storms(uber.com ↗)
    23comments
  17. Why I didn’t sign the Fields medallists’ letter(gowers.wordpress.com ↗)
    313comments
  18. The most important product decision is what you don't build(liamnugent.me ↗)
    19comments
  19. Rate limits on GitLab.com are changing(about.gitlab.com ↗)
    106comments
  20. How do we prevent mathemathics from devolving into the Medieval Era of secrecy?(mathoverflow.net ↗)
    56comments
  21. CCC invites all model citizens to 40C3(ccc.de ↗)
    180comments
  22. TSMC revealing details about next gen A14 node(mapyourshow.com ↗)
    36comments
  23. The American Religion of Self-Storage Facilities(newyorker.com ↗)
    344comments
  24. Landing the Space Shuttle – A Flying Machine and the Thrill of a Lifetime(eaa.org ↗)
    5comments
  25. Zettascale (YC S24) Is Hiring ASIC/FPGA Engineers to Build Chips for ASI(zscc.ai ↗)
    discuss
  26. Show HN: Snapdrop: Instantly share files between devices. No setup, no signup(snapdrop.me ↗)
    19comments
  27. Running Ubuntu on the Lenovo IdeaPad Duet(vhaudiquet.fr ↗)
    25comments
  28. Computer Reset, Dallas(dfarq.homeip.net ↗)
    2comments
  29. Launch HN: Skillsync (YC W26) – AI chat sessions made portable across agents
    50comments
  30. Show HN: Share your AI Setup, Learn from others(mysetup.ai ↗)
    103comments

Cage: Hardware-Accelerated Safe WebAssembly

1 pointsby 9mo agoarxiv.org
2 comments
9mo agoHN ↗

"Cage: Hardware-Accelerated Safe WebAssembly" (2024) https://arxiv.org/abs/2408.11456v2 :

Abstract: WebAssembly (WASM) is an immensely versatile and increasingly popular compilation target. It executes applications written in several languages (e.g., C/C++) with near-native performance in various domains (e.g., mobile, edge, cloud). Despite WASM's sandboxing feature, which isolates applications from other instances and the host platform, WASM does not inherently provide any memory safety guarantees for applications written in low-level, unsafe languages.

To this end, we propose Cage, a hardware-accelerated toolchain for WASM that supports unmodified applications compiled to WASM and utilizes diverse Arm hardware features aiming to enrich the memory safety properties of WASM. Precisely, Cage leverages Arm's Memory Tagging Extension (MTE) to (i) provide spatial and temporal memory safety for heap and stack allocations and (ii) improve the performance of WASM's sandboxing mechanism. Cage further employs Arm's Pointer Authentication (PAC) to prevent leaked pointers from being reused by other WASM instances, thus enhancing WASM's security properties.

We implement our system based on 64-bit WASM. We provide a WASM compiler and runtime with support for Arm's MTE and PAC. On top of that, Cage's LLVM-based compiler toolchain transforms unmodified applications to provide spatial and temporal memory safety for stack and heap allocations and prevent function pointer reuse. Our evaluation on real hardware shows that Cage incurs minimal runtime (<5.8%) and memory (<3.7%) overheads and can improve the performance of WASM's sandboxing mechanism, achieving a speedup of over 5.1%, while offering efficient memory safety guarantees.

Src: https://github.com/TUM-DSE/cage-meta

llvm-memsafe-wasm: https://github.com/TUM-DSE/llvm-memsafe-wasm :

A LLVM fork to implement MTE-based memory safety for WASM

wasmtime-mte: https://github.com/TUM-DSE/wasmtime-mte :

A fork of wasmtime to implement MTE-based memory safety for WASM

wasm-tools-mte: https://github.com/TUM-DSE/wasm-tools-mte

wasi-libc: https://github.com/martin-fink/wasi-libc

9mo agoHN ↗

This is awesome. Will chat with our team to see if we can implement it on Wasmer. Thanks for sharing!