https://chromium.googlesource.com/chromium/src/+/main/docs/s...
If you use a safe language like Rust, you can afford untrusted input and no sandboxing.
If you use an unsafe language such as C++, you must chose between trusted inputs or sandboxing.
I was curious as to where rfgplk's implementation lay within the Venn diagram.
> you can afford untrusted input and no sandboxing.
I would not trust a rust program un-sandboxed! There are security bugs in rust itself.