Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Firefox already has all that. A good part of the browser is written in JS which runs with high privileges (full filesystem access, full network access, etc) while the code on websites doesn't. It already has systems for unprivileged JS to request access to certain privileged APIs (location, localStorage, etc). "Apps" - websites - are already segregated and run in their own sandbox.


I know, and we have constantly lived along the edge of the cliff because of that. From a perspective of security it was a very poor design decision. By making those decisions you create a big security burden, the attack surface is very large, the impact of bugs is very large. These are the types of security consideration that have to happen at design time. In this case I would like to know more about, maybe it's being considered but not being discussed.


So you're saying sandboxing webapps are a bad design decision. What is your proposal then?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: