4 ms·
> The thing is, that logic applies just as well to desktop apps. A website might serve a different code every time you use it. It might even serve a malicious
by rom1v 5y ago
> The thing is, that logic applies just as well to desktop apps.
A website might serve a different code every time you use it. It might even serve a malicious code specifically for some users.
- mattl 5y agoA desktop app could do the same. It would be trivial to run a little bit of extra code if the person running the app’s username is yours.
- tuyiown 5y agoIf you consider arbitrary code execution for desktop apps you'll see that there's no much difference at a conceptual level.
- indymike 5y ago> A website might serve a different code every time you use it. It might even serve a malicious code specifically for some users. Desktop apps can do this little trick, too. Also, many desktop apps can enlist the help of other desktop apps using the three decades or so of various ways our OSes have made to lett apps talk to each other. Bad actors were using macro languages in desktop apps long before the invention of the web browser. Now, it's just as easy for a desktop app to hit an endpoint, grab a script (shell or macro language) and then execute it. The browser is just another desktop app - one with much more scrutiny than that MP3 tagging thing with a built in Lua interpreter that Bob in sales just gave local admin privileges to... Oh, and most desktop apps have some level of access to your identity - or outright have you confirm your identity when you activate your license.