A new word to bikeshed: Sandboxing.

7 views
Skip to first unread message

William ML Leslie

unread,
Aug 29, 2026, 2:41:06 AMAug 29
to Design
I just wrote the following to someone and can't help but wonder if you have some insight that maybe shouldn't be lost to history.

I should say, if you are researching security history, the term "sandbox" is a recent invention, and didn't originally refer to virtual machines etc. If you read older papers you may hear about isolation, domains, or even spheres of protection. The term "sandboxing" came out of malware research, and referred to emulating all of a machine, including attached peripherals, so that malware couldn't detect it was being virtualised. It was a sandbox in that it deliberately exists for the software to make a mess, without infecting a real machine.

I nicked those terms from Henry M Levy, but there are probably more.

Did anyone else notice that shift?  Is there more detail I am missing?  I'm not saying we should ignore that sandboxing does now mean this concept, but I think that history around this sort of thing can be enlightening.

Does anyone know of people using the term sandbox for this prior to 2009ish?

--
William ML Leslie

Mark S. Miller

unread,
Sep 2, 2026, 5:44:41 PMSep 2
to fr...@googlegroups.com
I see lots of current uses of "sandbox" that do not assume an emulation to hide the sandbox from the sandboxed code. Indeed, often the sandbox is obvious to sandboxed code because various abilities are missing in the sandbox, rather than being emulated.

That said, I like the narrow explanation you stated above. IMO, we need a new name for that narrower concept because it is too late to narrow the meaning of "sandbox".


--
You received this message because you are subscribed to the Google Groups "friam" group.
To unsubscribe from this group and stop receiving emails from it, send an email to friam+un...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/friam/CAHgd1hF%3D%2Bk5syg5t4Y7C9G2vuXC2zcAcKuib_%2BR4xDttbUg2MA%40mail.gmail.com.


--
  Cheers,
  --MarkM

Matt Rice

unread,
Sep 2, 2026, 7:28:54 PMSep 2
to fr...@googlegroups.com
On Fri, Aug 28, 2026 at 11:41 PM William ML Leslie
<william.l...@gmail.com> wrote:
>
I did a little looking through ngrams, and most of the early stuff I
found was late 90s java security model being described as a sandbox,

"We note that the term “sandboxing” was originally coined by Wahbe in
his seminal work on software fault isolation"
1993 https://dl.acm.org/doi/epdf/10.1145/168619.168635 Wahbe

there was one 1979 reference but it was unclear if it referred to
computer gaming or tabletop gaming, in
According to Ankur Taly's 2013 thesis at
https://theory.stanford.edu/~ataly/Papers/thesis-Ankur.pdf page 18
"Perspectives on Academic Gaming & Simulation" and I couldn't find
anything but short snippets without context
but it had a whole section 'Simulation in the sandbox'.

William ML Leslie

unread,
Sep 2, 2026, 7:42:06 PMSep 2
to fr...@googlegroups.com
On Thu, 3 Sept 2026 at 09:28, Matt Rice <rat...@gmail.com> wrote:
"We note that the term “sandboxing” was originally coined by Wahbe in
his seminal work on software fault isolation"
1993 https://dl.acm.org/doi/epdf/10.1145/168619.168635 Wahbe

Ooh, this is a good one.  Looks a bit like NaCl.

--
William ML Leslie
Plausible, not normative.
Reply all
Reply to author
Forward
0 new messages