←back to thread

78 points pjmlp | 1 comments | | HN request time: 0.419s | source
Show context
kstrauser ◴[] No.46189780[source]
> In the 2000's, politics interfered and browser vendors removed plug-in support, instead preferring their own walled gardens and restricted sandboxes

That's one way to say it. The more common way was that users got tired of crappy plugins crashing their browsers, and browser devs got tired of endless complaints from their users.

It wasn't "politics" of any sort that made browsers sandbox everything. It was the insane number of crashes, out-of-memories, pegged CPUs, and security vulnerabilities that pushed things over the edge. You can only sit through so many dozens of Adobe 0-days before it starts to grate.

replies(8): >>46189829 #>>46189834 #>>46189952 #>>46190045 #>>46190066 #>>46190195 #>>46190485 #>>46198543 #
exDM69 ◴[] No.46189829[source]
Exactly.

Java was so buggy and had so many security issues about 20 years ago that my local authorities gave a security advisory to not install it at all in end user/home computers. That finally forced the hand of some banks to stop using it for online banking apps.

Flash also had a long run of security issues.

replies(3): >>46190042 #>>46190048 #>>46190193 #
1. bigfatkitten ◴[] No.46190193[source]
I worked for a large financial institution in the early 2010s.

They ran Windows XP, IE 8, and they stuck with a 3-4 year old JRE to support one piece of shit line of business app that was used only by about 100 (out of 50,000) users internally.

That institution had endpoints popped by drive-by exploit kits dropping banking trojans like Zeus daily.