3 ms·
As much as they try to add security to this feature it inherently breaks out of the "sandbox" concept of the browser and scares me.
by randtrain34 6y ago
As much as they try to add security to this feature it inherently breaks out of the "sandbox" concept of the browser and scares me.
- ausjke 6y agonowadays' security is that you have to manually grant permission, which for most people, esp non-technical people, they will normally just press Y, so yeah, the default sandbox protection will be gone for most people.
- cromwellian 6y agoYou have to do more than just hit 'Y', you have to navigate in a file chooser and pick the file to save, or write.
- anaganisk 6y agoSure why not, let me just create a blog post, with exact steps on how to make your windows more colorfull, and make users inject my DLLs into filesystem. The user will do exactly if i give him exact copy paste paths and commands. And voila.
- cromwellian 6y agoYou can do the same exact thing without this API, so what’s your point? How do you think most call center scams work? By asking the user to download an executable that owns their system and run it.
- yjftsjthsd-h 6y agoIt's possible for this to reduce steps / make the exploit process easier, and to do so without the "download this file and run it" step that should trigger a red flag to people.
- pjmlp 6y agoWith WebApps, it is enough to exploit sandbox contents itself.