Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the web context, iframes are reasonably safe (if you discount ad privacy issues).

One of the touted advantages of Electron is that you can use web technologies and thus have engineers familiar with web technologies working on your application.

It’s very easy to see a web developer do what is perfectly fine on the web.

Heck, this feature might even have been added for their web client and then brought over to the electron version, possibly unbeknownst to the original author of the feature.

No. I wouldn’t call this a bug screwup. Just another effect of the footgun that is electron



> In the web context, iframes are reasonably safe (if you discount ad privacy issues).

This is a dubious claim; not sure how long you've been developing for the web, but iframes have had many many exploits fixed over the years. That's neither here nor there though, as Discord purports to be a native application and therefore should be extra careful.


You can say that about any major piece of tech being used on the internet, right down to the microcode running on your processor having issues. I mean, shit windows had ANOTHER ping of of death style exploit this month. Should we just stop using windows? What about all the linux exploits that exist?


It is more like use ChromeOS technologies thus Web developers don't have to bother writing portable Web applications.

Slack doesn't do anything so amazing that cannot be a portable Web application, with the browser I already have installed.


That's the thing. In the web browser everything is isolated. With electron you get full access to the system.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: