4 ms·
Regardless of the discussion, Electron browsers are very insecure and is not a stable foundation to build a browser on. Electron even recommend that you do not
by Havelock 6y ago
Regardless of the discussion, Electron browsers are very insecure and is not a stable foundation to build a browser on. Electron even recommend that you do not try and build a browser using it.
- eivarv 6y agoThis. Brave famously migrated away from Electron because of the security implications of that approach. Also, it kind of makes sense: You'd effectively be implementing a browser (or the GUI thereof) in a browser.
- inopinatus 6y agoif the underlying language were Lisp or Smalltalk then implementing it thus might be a rational shoo-in.
- eivarv 6y agoI don't know. Implementing a browser in a browser can make XSS potentially bad, and I think it even lead to full on RCE in the earlier days of Brave/Electron. Still happens, I think (though to a lesser extent these days). There's also the difference in time between committed patch and end user having a new release in the case of a critical vulnerability, for instance. Using an embedded browser framework introduces many intermediate parties, some (many?) of which might not have being up to date with the upstream as a priority – which leads to a weakened state of security in the "browsers" downstream.