Hacker News new | ask | show | jobs
by yjftsjthsd-h 3045 days ago
Well yeah. The appropriate reaction here is to assume that the company is shipping malware in the product regardless of what particular format.
1 comments

Sure, but what of significance has changed? Every time you run a program, you're trusting the developer not to do nefarious things like reading your Chrome credentials, because the only assurance you have is the developer's word about what the program does. As far as I can tell, that hasn't changed at all. I'm not saying this is okay - there are reasons why this is a bad thing to do, I just don't see how no longer being able to trust the developer not to be malicious is one of them.
There is a difference between "developer could hypothetically do bad stuff" and "developer has been caught doing bad stuff"