Hacker News new | ask | show | jobs
by g_p 1262 days ago
Indeed - this was my first concern. How many of these local web servers are properly implementing CSP and the myriad of other protections you need to (securely) run a local web server that isn't vulnerable to CSRF from other origins etc?

Zoom fell foul of almost exactly this before it became popular during the pandemic. https://www.theregister.com/2019/07/11/apple_removes_zooms_d...