Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When there would be a bug in PDF processing, you end up with a RCE, right?

But downloading an EXE is basically allowing arbitrary code execution on your machine no matter what. So _even with the security bugs_, webapps are basically safer than installing a native app on desktop, at least in its current state.

I see your point though. There are still a lot of entry points we need to be careful about



It doesn't help that curl | sh has become trendy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: