logoalt Hacker News

Dylan16807yesterday at 11:52 PM1 replyview on HN

If it was a native app it wouldn't be grabbing one of the hosted files and running it as code.


Replies

streetfighter64today at 12:11 AM

Have you never seen a native app's auto-update get hijacked by malware? It happened (yet again) last month [0]

Tons of native apps also have plugins or addons, which (surprise surprise) is just code downloaded from some central repo, and run with way less sandboxing than JS.

[0] https://www.bleepingcomputer.com/news/security/notepad-plus-...

show 1 reply