Conversation

> App security for other platforms generally involves code analysis to see what it does, rather than denying access to APIs. But Google made a decision to restrict APIs ... oh, you would simply statically analyze the javascript to know if it's bad. intriguing
3
55
there's an appeal to the code review processes of app stores, like they're good. and then i see infosec people playing along like this is tractable
2
26
Replying to
The approach of moving to a declarative content filtering API instead of extensions using invasive access to every web page is an important improvement even if you trust the developers of the extensions. They're currently opening up weaknesses in the site isolation sandbox.
1
1
Replying to and
There has been a ton of work to make the process boundaries into internal security boundaries by implementing the semantic isolation between sites and the restrictions on them at the process level. Extensions run as one process messing around with all of them at the same time.
1
Replying to and
It's a given that journalists usually have a weak grasp of the subject matter and are heavily influenced by press releases and marketing. Seems particularly bad for tech journalism and especially anything to do with privacy or security. They paraphrase marketing / press releases.
1