Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you feel like the only thing preventing you from understanding the security risks of executing a piece of Javascript in Chrome is the parts of the source that are used only in Chrome and not in Chromium, you have a very high opinion of your ability to reason about that many lines of non-memory-safe code that I think is not backed up by the evidence.


No, I think I have a low opinion about my abilities - I need a complete picture and all the help I can get to understand anything at all.

But yes, I agree that it's not as simple as my original comment made it out to be - I definitely failed to fully acknowledge that most/some of the critical parts are open source and secured, but I think the incompleteness in any outside understanding (such as my own) is a major factor in the options Google could present about security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: