Hacker News new | ask | show | jobs
by txutxu 4731 days ago
I think there is more danger in html5 dinamyc fonts, or more evil in a dns request, than an opensource project installer.

Of course, don't do this on your most beloved production machine, if you can package it properly, test it, etc

But rendering a font gives execution with your user, so don't be so afraid of a installer "you can read" and has an interesting purpose.

1 comments

"But rendering a font gives execution with your user"

Would you point us to a reference, or a further explanation for this claim ? I am genuinely interested...

Sure, it was just an example...

http://securitytracker.com/id/1024283