Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The web got it because for some _insane_ reason, websites were able to convince IT departments to allow scripts to run.

That left the barn door unlocked. Suddenly the download everything every time (or hope some is at least cached) environment of JavaScript / ECMAScript became the ONE place a user could 'for sure' 'install' (run someone else's unapproved) program.

-

Websites, _really_, should work just fine with zero scripts turned on. Possibly with the exception of a short list of trusted or user approved websites.



As opposed to native apps like the parent poster is proposing with no sandbox and that need to be created for each platform?


As opposed to applications authorized by professionals in charge of equipment.


???




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: