Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How can the permissions mechanism be fine grained enough to prevent bad random things, and coarse grained enough that you can understand it?


Requesting site access by click or by URL really isn't rocket science.

Not nearly every user will get it right, so extensions will probably still have to be monitored for malware for the foreseeable future, but it gives many users at least a chance at privilege minimization.


Have you seen AWS IAM?

Power users who care about this don't need a GUI - a text file config in any format will do. Especially in this era of LLM assistance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: