3 ms·
I completely agree. The rapid flux in these huge browser projects makes personal security audits impossible even if you are one of the top 10 super-rigorous C++
by rphlx 8y ago
I completely agree. The rapid flux in these huge browser projects makes personal security audits impossible even if you are one of the top 10 super-rigorous C++ devs in the world. Would be nice if some project forked the browser of their choice and then got some very careful well-respected teams/rockstars to audit it, and from then on, applied only security fixes and outright-rejected dubious stuff like WebUSB, google auto-login, etc. With Chrome and Chromium, sure, you get a very good security team working on it for you at Google, but you also get changes which are not in your best interests and/or undermine security directly or indirectly like, well, WebUSB. This is not ideal.