Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
zetafunction
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
13 ms
·
31.
▲
by
zetafunction
9y ago
This is what Chrome already does: it uses a utility process to host the common file dialog. See https://cs.chromium.org/search/?q=CallGetOpenFileName&sq=pac...
32.
▲
by
zetafunction
9y ago
Two other reasons that haven't been mentioned yet: - MSVC had trouble with dead code elimination in some cases: fixing https://crbug.com/684105 reduced binary size by almost 900KB on Windows. - It lets tooling like ht
33.
▲
by
zetafunction
10y ago
Chrome for Android blocks autoplaying videos. To get around this, sites now use JS to decode and render video into a canvas. For example: https://bugs.chromium.org/p/chromium/issues/detail?id=178297... . As on
34.
▲
by
zetafunction
10y ago
Actually, both Chromium [1] and Firefox [2] are working on showing plain HTTP as insecure. [1] https://blog.chromium.org/2016/09/moving-towards-more-secure... [2] https://blog.mozilla.org/tanvi
35.
▲
by
zetafunction
11y ago
Imagine a more powerful API existed that an extension could use to control other extensions. Now the badware extensions start using the more powerful API and you're back to square one...
36.
▲
by
zetafunction
11y ago
From the article: Are Firefox extensions any better? To be honest, no.
37.
▲
by
zetafunction
11y ago
The interstitial for blocked content is implemented on a per-page level. You can test this yourself by creating a test page with an iframe to http://ianfette.org . Suppose that Chrome just tried to replace the malicious embedded
38.
▲
by
zetafunction
12y ago
As a Chrome developer, I agree that process-per-tab absolutely should not be a replacement for fixing bugs. However, I think it's important to point out that process-per-tab is not just for stability: it's also critical for securi
39.
▲
by
zetafunction
12y ago
> What's the mindset that ends up with Chrome going out of its way to swap OK/Cancel when you enable DNT? Chrome dev here. The way the Chrome settings web UI is written does not lend itself to strong consistency, just eventual,
40.
▲
by
zetafunction
13y ago
This is neat... but why not use the copy/paste event handlers where possible?
41.
▲
by
zetafunction
13y ago
Oh oops. I left out the link to the sample in my last post: http://jsfiddle.net/BE6bR/1 Try it out =)
42.
▲
by
zetafunction
13y ago
I'm not sure, but several guesses: 1) The clipboard APIs aren't well known. 2) You can't normally set HTML content in the clipboard with IE since it only supports 'Text' and 'URL' types ( http://
43.
▲
by
zetafunction
13y ago
Normal web pages can't trigger copy/cut/paste events. They can access the clipboard via the events (which are automatically fired when the corresponding action is invoked by the user) documented in http://dev.w3.
44.
▲
by
zetafunction
13y ago
> When you say, deny, to me the user must go to their browser settings and set it manually? AFAIK: Safari does not expose a setting for this (but I didn't look). Chrome uses Chrome app/extension permissions to control this sett
45.
▲
by
zetafunction
13y ago
There is a way to trigger the events from JS via document.execCommand('copy'/'cut'/'paste'), but the default is to deny. However, if you just want to alter the behavior of ^C, you simply need to overr
46.
▲
by
zetafunction
13y ago
Why aren't the copy/cut/paste events be sufficient for this? There's no need to trigger a programmatic copy event in this context, since you're just modifying the default behavior of copy.
47.
▲
by
zetafunction
13y ago
Google is using SSL with ECDHE which provides perfect forward secrecy. Having a copy of the SSL certificate won't do the NSA any good.
48.
▲
by
zetafunction
13y ago
A privileged user has nothing to do with it. Running as a non privileged user will not stop keyloggers, cookie theft, privilege escalation exploits, etc.
49.
▲
by
zetafunction
13y ago
Multiprocess is also important for security. It means that simply finding a renderer exploit isn't enough to pwn your system if the renderer processes have no privileges to write/execute arbitrary files.