Hacker News new | ask | show | jobs
by vvillena 2692 days ago
Surely the capability to deliver JS is still there, even if you're a premium user. This is worrying.
1 comments

Yes, that happens basically with any app you run on your computer, duh.
Capability + intent is what counts in this case. They intend to deploy countermeasures targeting a minuscule percentage of people, but every user will probably feel the consequences. This, plus the fact that they are willing to serve JS from third parties, is a dangerous mix. It's not what you would expect from a music player app.