• @aluminium
    link
    2711 months ago

    Bruh, I actually prefer the “Web 2.0” solution. That way the god damn editor can’t just start accessing all the shit on my drive.

    • @[email protected]
      link
      fedilink
      4911 months ago

      Lol but included in the source for www.texteditor.com is analytics, beacons, etc from Google, Microsoft, Facebook, Twitter, Cloudfare, and a bajillion different ad networks that send the content of your text file to AI models.

    • @[email protected]
      link
      fedilink
      36
      edit-2
      11 months ago

      My text editor doesn’t access shit on my drive (unless I ask it to) because it’s Free Software and my Linux distro package maintainers audit it to make sure it doesn’t contain malware like that.

      You’re praising a pathological solution to a problem that shouldn’t exist to begin with.

      • @Takumidesh
        link
        1311 months ago

        Forever audits of free software are unsustainable in my opinion.

        To truly audit every piece of software, you need an independent party to spend time (often more than the development) to look through the code, that person needs to be equally or more experienced than the developers of the software, and have specific knowledge for vulnerabilities and malicious techniques.

        They then need to audit and monitor all of the channels of distribution for that software, including various websites and repositories. This needs to be done constantly.

        You effectively need to double or more the total level of effort for all software.

        Yes, high profile software (sometimes) gets audited regularly, but the assumption that anything you grab from your package manager has been truly audited leads to a false sense of security, additionally the assumption that an audit being performed means there are no issues with the code also leads to problems.

        The reality is that most open source software doesn’t get audited because it is too much work.

    • ZILtoid1991OP
      link
      fedilink
      1411 months ago

      Wait until you meet with Javascript and WebAssembly viruses!

      • nick
        link
        fedilink
        111 months ago

        WebAssembly is sandboxed and deterministic. Any impure code has to be triggered via message passing with the host language.

    • @BurnedOliveTree
      link
      311 months ago

      That’s why there is sandboxing on macOS and in Flatpacks