Skip to content

Comment on Silverlight Has the Exact Same Vulnerability That WebGL Does

Comments

Beyond the self-serving statements that most everyone involved in this story are making, there's a real issue here. That Silverlight has (or had) vulnerabilities of the sort that make Microsoft hesitant to implement WebGL is ironic, but it's also interesting because it shows that they've got a point that such vulnerabilities can be a problem.

This storyline, like so many others, serves as an occasion for people to line up with one team or another and make whatever arguments support Google, Microsoft, Apple, Facebook, or whoever they're rooting for.

But obscured behind all that smoke is a subtle, nuanced conversation to be had about the problem itself: What are the essential performance vs security tradeoffs? What can be done about them? And then there are larger issues, like this: A curated app store model where code is vetted and apps are run in a sandbox might significantly reduce users' vulnerability to attacks like this, but at what cost, both to users, developers, and those running the app store?

The other story is to what extent is a private company obligated to implement a feature pushed by its competitors? This is often done in the name of it being a "standard", but C# is standardized too.

Furthermore, these standards often haven't been well vetted. As I noted before C++ ran into this problem with export. It caused no end of headaches and wasted time. It was eventually effectively dropped (although EDG did appear to get a decent implementation in-place finally).

At the end of the day each vendor should feel they have the freedom to implement what they deem as important. Other vendors should respect it. Whether its Apple not supporting Flash (not a standard, but hugely popular) or MS not supporting WebGl (a draft, but not widely used).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.