2 ms·
The security needs to be in the browser - as in the user needs to enforce the security, not the code - leaving it up to developers to specify what permissions t
by gdp 17y ago
The security needs to be in the browser - as in the user needs to enforce the security, not the code - leaving it up to developers to specify what permissions things should have is a recipe for lazy developers getting us into a situation much like the one we're in now.
- axod 17y agoI agree! Improve the BROWSER security model. Javascript is an innocent bystander in the mess. It's the browser that allows 20 scripts from different domains all come together in the same execution context each with full permission to do anything.
- gdp 17y ago> Javascript is an innocent bystander in the mess. No, it's not, because well-formed, valid Javascript code is permitted to depend on this execution model.
- axod 17y agoYou're not making any sense whatsoever any more. The decision to combine 20 <script> sources into the same execution context is the BROWSERS decision. NOT javascripts. It's the BROWSER that doesn't have any concept of allowing <script> fine grained permissions within the execution context, or specifying you'd prefer if the browser put that script in a separate execution context. It's the BROWSER that needs fixing here, not js.
- gdp 17y agoI'll refer you to this comment now, as we appear to be arguing about the same thing in two threads: http://news.ycombinator.org/item?id=843320 http://news.ycombinator.org/item?id=843320