logoalt Hacker News

bigrocketappsyesterday at 1:43 PM2 repliesview on HN

If you tried this out in Linux, for example, the system would block you from selecting folders that contain files that are flagged as dangerous or "system files". I'm assuming this was implemented across all OSes.


Replies

blharryesterday at 2:01 PM

That does not sound at all reassuring, that the only safeguard is the system blocking access and that the API has no safeguard.

Its also easily possible to have sensitive files misplaced, especially for a general non-technical user that would be the one falling for a browser hijacking attack

show 1 reply
znpyyesterday at 2:34 PM

i give zero F about whatever is in my /usr, /var/lib and /opt folders.

what are websites gonna steal, debian binaries and libraries?

all my important stuff are in my home directory, which is owned (read+write) by me, the same user running the browser.