Join Nostr
2026-09-07 02:44:01 UTC
in reply to

mleku on Nostr: even a normal web app that excludes loading anything with code is safe enough. but if ...

even a normal web app that excludes loading anything with code is safe enough. but if you look through the source code of the jumble web app you will find it loads all kinds of other apps into it. you can see on mine, the youtube doesn't load a youtube player into it. it fetches the thumbnail and you click it and it opens a new page. i did that because that thing streams all mouse movements constantly on the whole page. this is precisely the kind of thing i'm talking about.

when it comes down to it, the normie has no way of determining the safety of the app, even if it's native. the real issue is that YOU check your code doesn't leak or give access to secrets. if you can get a clanker to build an app, you can ask it repeatedly to verify there is no remote code running within it, and that nothing within it is going to leak outside the browser runtime. exploiting browsers is something that has been a problem for years and for which reason all known holes are already closed.