Hacker News new | ask | show | jobs
by samwillis 4023 days ago
The binary blob is targeted at Native Client and so only runs in the google chrome sandbox. There is no security issue here.
2 comments

"Don't worry, it's running as restricted windows user, there is no way it could possibly ever... oh"
Sandboxed unknown code is still better than non-sandboxed unknown code.
Agreed, but it is not the same thing as saying there is no security issue.
We are totally secure because all of our Windows users run with limited privileges!

...that is until the domain admin checks his email and opens a malicious PDF.

But it's closed source, which is a criterion that Debian have historically regarded with a very high priority.