Hacker News new | ask | show | jobs
by TheCapeGreek 777 days ago
That's a problem with just about any package, library or system you use in the end.

Open source runs in a large amount of trust, and we're all complicit.

1 comments

Sure, but these types of applications are running in a web browser sandbox, which benefits from enormous engineering resources to protect the host computer from malicious actions by the remote code. I'm wondering whether this execution environment (augmented with some policy mechanism to allow apps to declare their URL access needs, a little like an AppArmor or network firewal policy) could also provide some guarantees concerning privacy or information security.