3 ms·
> there is no intrinsic reason why code from one vendor ... should be more or less secure that from the OS developer If you're writing a cross-platform applica
by twr 10y ago
> there is no intrinsic reason why code from one vendor ... should be more or less secure that from the OS developer
If you're writing a cross-platform application, it's often easier to be confident in platform-agnostic parsing code that uses the platform sandboxing primitives, versus yielding parsing to the operating system, which may decode in a different execution context, and be less secure compared to the application security policy.