Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Actually, history does not show that low-end mass malware moves to more advanced techniques and you CAN predict the vulns they'll target in advance, as long as you're familiar with their motivations, capabilities, and incentives. http://www.trailofbits.com/research/#eip

Again, show me an actual attack that has exploited Safari. Ever. Targeted, mass malware, I don't care. Apple has better shit to worry about and their investment in Seatbelt was worth 1000x more than individually fixing the limitless supply of bugs in Webkit. Problem solved, move to next actual issue.



You can scope the discussion to mass malware on desktop Safari, but that's just reductio ad absurdum. Any fortune 500 or government has to be concerned with real attacks, not just tamping down the noise floor. And as for Apple, they've historically been more interested in protecting their manufacturer subsidy by stopping iPhone jailbreaks--in which WebKit exploits against Safari have played a key role.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: