Hacker News new | past | comments | ask | show | jobs | submit login

They are using node-webkit which means any javascript has unrestricted access to the nodejs api http://nodejs.org/api/. It wouldn't be hard to do something malicious with those low level filesystem, network and process modules.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: