Hacker News new | past | comments | ask | show | jobs | submit login

If you cannot audit it and supervise it, do not offer a point-and-click way to install it. Do not rely on end-users experience and sanity nor the good intentions of random people online.

Installation of Gnome extensions or KDE themes (unless official package from distribution's repository is used) always seemed as unnecessary risk to me.




I posted an idea about sandboxing that I think is a middle ground between doing away entirely with the idea of gnome/kde extensions and themes using sandboxing:

https://discuss.kde.org/t/sandbox-plasmoids-by-default-to-pr...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: