Hacker News new | past | comments | ask | show | jobs | submit login

Sounds like a security hole: non-whitelisted malicious app launches whitelisted app as an external process, and then mayhem ensues.



User permission should be required when launching external processes.


And whitelisted processes don't have to take input from anything other than the user himself; a command-line screenshot tool that can be run by any program and doesn't ask for interactive confirmation through a trusted channel (ie. keyboard events directed into its own window by the compositor itself) would be a pretty stupid thing to whitelist unless you've got proper sandboxing for any untrusted apps.




The deadline for YC's W25 batch is 8pm PT tonight. Go for it!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: