3 ms·
Because its the securest way we have to launch any app on any device. With binaries, any binary might be malicious and therefore I can only trust and run a very
by mschuetz 4y ago
Because its the securest way we have to launch any app on any device. With binaries, any binary might be malicious and therefore I can only trust and run a very small amount of selected binaries. With web apps, I can launch whatever I want without compromising my system.
- autoexec 4y ago> With web apps, I can launch whatever I want without compromising my system. What makes you think web apps can't enable exploits that compromise your system? Anything that can run code on your machine enables attacks. Even Javascript that gets run in browsers have enabled attacks on the local system. If anything web apps decrease your security since a binary can be vetted and verified as unchanged, but when you open a web app you're at the mercy of whatever it is and does in that moment.
- zarzavat 4y agoThat may be plausible in some limited cases (iOS) but on most platforms opening an untrusted native app is much more risky than opening an untrusted website. For example, a native app has access to the file system, which is all that is necessary to enable ransomware attacks.
- autoexec 4y ago> For example, a native app has access to the file system web apps also have access to the file system, although there are extra steps https://developer.mozilla.org/en-US/docs/Web/API/File_System_Access_API https://developer.mozilla.org/en-US/docs/Web/API/File_System... Here's a shell! https://rreverser.com/webassembly-shell-with-a-real-filesystem-access-in-a-browser/ https://rreverser.com/webassembly-shell-with-a-real-filesyst... Webassembly is overwhelmingly used for malware (https://www.crowdstrike.com/blog/ecriminals-increasingly-use-webassembly-to-hide-malware/ https://www.crowdstrike.com/blog/ecriminals-increasingly-use...) but at least it's usually just mining cryptocurrency. I'd guess it's only a matter of time before it's commonly used for much worse.