3 ms·
An alpha release of a new browser engine is likely to have quite a few security bugs. Don't risk your bank account details for the sake of testing a new browser
by thomasfoster96 11y ago
An alpha release of a new browser engine is likely to have quite a few security bugs. Don't risk your bank account details for the sake of testing a new browser engine.
- slimsag 11y agoFair point. Not trying to minimize what you're saying -- But I am genuinely curious as to how you'd test such a vast code-base written by so many different people for security issue? e.g. how will 1.0 be any more secure than alpha aside from developers having more time to "run into" the security issues by sheer luck/accident? Maybe someone vet the code by hand -- or maybe they will use a security testing suite to automate it? If so, wouldn't it make sense to do that before accepting code that could potentially introduce security bugs?
- toyg 11y ago> how you'd test such a vast code-base written by so many different people for security issue? I think their point is that correct, well-thought-out and well-tested code (i.e. doing exactly what it needs to do, without side effects and errors) will inherently be more secure than any hacked-together it-runs-ship-it MVP/alpha/demo release (which is what Servo is, at the moment). Security-specific tests would be done in the same way as they're done for any mainstream engine out there.