Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is inherently a security problem because web sites can open URLs without user awareness or deceive users about the content of said URLs.

On Ubuntu, xdg-open phrases the checkbox as something like "always allow X program to handle foo:// URLs?", which is probably not comprehensible to the average user; more accurate phrasing would be "always allow websites to open X program?" Which I think indicates why I'm so skeptical that this is a good option to give to users.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: