Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At some point we'll need to weigh security vs usability... I'm getting tired of seeing my browser becoming less and less open.

Can we not put somekind of VM environment around the entire browser, so that it's not an entry door to someone's OS ?



The security issues with alert is not about getting access to the OS, but having a third-party (cross-origin iframe) display a message to the user, when the user doesn't know that the message is not from the site they are visiting.


they say they want to get rid of first party alert as well though, and don't offer any sort of opt-out for trusted iframes


They also could very well improve the cross-origin alerts to say "This message is from ANOTHER website embedded in this tab, please act carefully. (source: xxx.com)" instead of outright removing it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: