logoalt Hacker News

asadotzleryesterday at 8:26 AM0 repliesview on HN

When a vendor bundles their own code with Webkit, it's quite easy for that vendor's code to have it's own security vulnerabilities, yes commonly in the UI, but also to open security vulnerabilities in Webkit. There's also no telling how much they've modified Webkit itself to make the rest of their code work. You simply cannot trust it and there are many security failure modes here. If you cannot inspect it all, you are trusting the vendor and I would be very careful trusting un-tested vendors of the most complex programs ever written which hold your credit cards and all of your logins probably your bank as well. I damn well would not trust the first few versions before the white hats have had a few years poking at it.