back

by Lammy·6y ago·view on hn ↗
RE: #1, I think it’s probably just one of those assumptions that passes over our collective heads until we have a wake-up call, like the need for TLS over leased fiber in the wake of the PRISM/MUSCULAR revelations. I could totally see a hypothetical “chain of changes” that lead to something like a lack of exploit mitigations on internal/preference pages. Those kind of interfaces used to be implemented with native OS GUI controls (or some facsimile like XUL), and I assume the collective thinking toward their security didn’t get rethought much when Chrome et al implemented them with web controls. Considering I’m here commenting about it and not discovering this myself just makes me thankful these things get found at all :)