Simple Browser Security Improvements 0 ▲ text/plain 2 hours ago · Tech · hide · 0 comments Security Engineering is all about tradeoffs: Security vs. Privacy Security vs. Performance Security vs. Compatibility Security vs. Usability Web Browsers attempt to achieve an absolutely bananas goal: Allow safe execution of untrusted content on a user’s device. Browsers are a huge vector for compromise of users’ devices and personal information, owing to the power and complexity. Much of the vulnerability induced by browsers occur where tradeoffs were either made poorly initially, or where the tradeoff would be made differently knowing what we know now. So, what should we do? Here’s a modest list of proposals, many of which could be achieved in less than one dev day: Disallow random websites from going fullscreen without permission Allow simple Enterprise control of what types of files are allowed to download — current controls are comically underpowered. (https://issues.chromium.org/issues/40265750) Block download UI launch of high-risk file types that the OS has inexplicably failed… No comments yet. Log in to reply on the Fediverse. Comments will appear here.