4 ms·
In a sense Microsoft forgot its own learnings. Because of exactly things like this they prevent UWP apps from connecting to localhost by default and make it ver
by 2ion 5y ago
In a sense Microsoft forgot its own learnings. Because of exactly things like this they prevent UWP apps from connecting to localhost by default and make it very annoying to circumvent and from my experience, the circumvention is not exactly a stable setup. So they really don't want you to do that, and somebody thought enough to make it extra difficult. So, they have UWP, all those well thought-out policies, then make an editor ecosystem out of web technology and throw everything out of the window. No surprise from a $T company with more teams than countries on Earth that not everything is coordinated, but they should have a guy with the required knowledge and sensibilities on any major product team. Apps installed from their "store" are relatively safe, but then they put a (extension) store inside their app again, which is unsafe :/
- easton 5y agoApps installed from the Microsoft Store are no longer guaranteed safe, as Win32 apps can be added to the store now and installed via winget. There’s static analysis and they run the installer, but if it does something stupid after the install they can’t automatically detect it.
- withinrafael 5y agoAnd it was unsafe for a few years prior to this event too, with the introduction of Desktop Bridge apps (packaged Win32 hybrid apps running with full trust).
- garren 5y agoDon’t the win32 apps restrict the calls in that subsystem that one can access? I recall looking into this a while back with the intention of leveraging it for an ancient win32/mfc app. I don’t remember the specifics, but I seem to recall that MS restricted or prevented access to a rather substantial subset of win32.
- WorldMaker 5y agoNot anymore. Microsoft gave up on trying to sandbox Windows Store installs for Win32 apps.
- 2ion 5y agoThat's good to know. It was still locked down when I looked into it last time.