Hacker News new | past | comments | ask | show | jobs | submit login

> Removing support for dead formats is generally a very good idea, particularly in a web browser, because it reduces the attack surface;

This seems unfortunate, surely they could sufficiently sandbox the decoder




They do, but it's defense in depth


Yet websites can run arbitrary JS?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: