3 ms·
> So websites can now nag users to allow access to the root of their local disk No, Chrome doesn't allow this. Here's a simple demo: https://output.jsbin.com/
by jaffathecake 4mo ago
> So websites can now nag users to allow access to the root of their local disk
No, Chrome doesn't allow this.
Here's a simple demo: https://output.jsbin.com/kekekac/quiet https://output.jsbin.com/kekekac/quiet - note that you can't select root, Downloads etc.
- deleted 4mo ago[deleted]
- move-on-by 4mo agoAh yes, totally secure. I’m sure there will be no unforeseen problems or bypasses.
- streptomycin 4mo agoIt's been in Chrome for 6 years and I'm not aware of any problems it's caused.
- croes 4mo agoYet. It’s not hard to imagine a case where it is a bad idea to give the browser access to the whole content of a directory. There is a reason why it’s Chromium browsers only, don’t you think?
- rcxdude 4mo agoJust because a problem is not hard to imagine it doesn't mean that the problem is actually a problem in practice. It is worth asking if there are any signs of it existing for real.
- croes 4mo agoI hear a lot of this "nothing has happened so far" from people who DUI before their first crash and people who use the same password on multiple sites before their first credential stuffing hack
- rcxdude 4mo agoto use your analogy you're claiming that half the population has been driving drunk for years and yet you aren't pointing to an increased rate of collisions on the road. This is not the same thing as an individual doing a dumb thing and getting away with it for a while.
- croes 4mo agoCould it simply be because many use their smartphone to browse the web and of those many have an Apple device and Safari based browsers don't support that API? It's like the eraly claims that MacOS has no viruses. No the bad guys jsut didn't care enough because the ROI wasn't big enough
- streptomycin 4mo agoSo what should I do if I want to make an app with this functionality? Do I have to tell users to download and run some executable? You can imagine a case where that is a bit riskier than a nicely sandboxed web app with permission to access one directory.
- danaris 4mo ago> Do I have to tell users to download and run some executable? Well, yes. The alternative is to give any malicious ad the ability to drive-by-download malware onto your machine.
- modeless 4mo agoDid you miss that this has been shipped in Chrome for 6 years? How many drive-by-download viruses has your machine gotten since then? Zero for me...
- danaris 4mo agoMine? None. Because I don't use Chrome. It's spyware.
- deleted 4mo ago[deleted]
- streptomycin 4mo agoWell there is a permission dialog and you need to select the directory to grant access and common sensitive directories are blacklisted. A malicious ad would probably have an easier time tricking you into downloading and running an executable, which is something that has actually happened many times IRL. Worry about that before worrying about theoretical exploits that nobody has actually exploited in an API shipped in the world's most popular web browser for the past 6 years.
- croes 4mo ago
- leptons 4mo agoApple will never implement anything in a browser that could make a web app as capable as a native mobile app, they are simply too greedy. Firefox typically doesn't implement these things unless they have to because they don't have the resources that Google and Apple do.
- steveharrison 4mo agoI hadn't thought about this angle as to why WebKit hasn't implemented this, but yeah 100%.
- leptons 4mo agoApple is also on the W3C committee that approves new specs, where they abuse that power to prevent any spec that might cut into their app business from moving forward.
- fg137 4mo agoI'd argue this is because it's rarely used.
- croes 4mo agoIn this example https://web.dev/patterns/files/open-a-directory https://web.dev/patterns/files/open-a-directory I can select Downloads
- codedokode 4mo agoI could select /boot and ~/.cache. Genius. Given how smart are many Internet users this will definitely not cause any misuse.
- ThatMedicIsASpy 4mo agoAfter seeing a recaptcha with a QR code. Suddenly those fake recaptchas with a run dialog don't seem too far fetched.