I agree that the developer has to check that the code doesn'...

npub16xnpfx85k8wzdhctang6860g3u64lds5kac73ddjwlg0lxdg9g3su56z6l
hex
9ef112b69109acc84f5a26ebddbd9baf7d29bfeed8feee4248812a6e85b952d2nevent
nevent1qqsfaugjk6gsntxgfadzd67ahkd67lffhlhd3lhwgfygz2nwsku495sprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsdrfs5nr6trhpxmu97e5dra85g7d2lkc2twu0gkke8058lnx5z5gcg8u0feKind-1 (TextNote)
↳ Reply to Event not found
bf5fde8b9748537a75db369280f7f6ff060223955c69d8b2648e83bd92430350...
I agree that the developer has to check that the code doesn't leak or give access to secrets, but I don't think that developers should have confidence that they were in any particular case able to do so successfully.
Also, repeatedly asking an AI that there is no remote code running within an app and that nothing is leaked outside the browsers runtime is certainly a good idea, but it provides at best very limited reassurance that your app actually doesn't hvae these defects.
And that "all known holes" in browsers are already closed is likely true where such holes are publicly / widely known, but it doesn't provide reassurance against unknown holes, or holes only known by a small number of people.
Raw JSON
{
"kind": 1,
"id": "9ef112b69109acc84f5a26ebddbd9baf7d29bfeed8feee4248812a6e85b952d2",
"pubkey": "d1a61498f4b1dc26df0becd1a3e9e88f355fb614b771e8b5b277d0ff99a82a23",
"created_at": 1788750243,
"tags": [
[
"e",
"71548e70da7ec315931758f97acf0006df89cfae4fff8245142b5dcb522dd9a8",
"wss://basspistol.org/",
"root",
"3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
],
[
"e",
"bf5fde8b9748537a75db369280f7f6ff060223955c69d8b2648e83bd92430350",
"wss://relay.primal.net/",
"reply",
"5538e28a66eb88360f15f8fa95646bdd2daa2999aacfe4faacf43d0c0540b281"
],
[
"p",
"3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
],
[
"p",
"efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19"
],
[
"p",
"5538e28a66eb88360f15f8fa95646bdd2daa2999aacfe4faacf43d0c0540b281"
]
],
"content": "I agree that the developer has to check that the code doesn't leak or give access to secrets, but I don't think that developers should have confidence that they were in any particular case able to do so successfully.\n\nAlso, repeatedly asking an AI that there is no remote code running within an app and that nothing is leaked outside the browsers runtime is certainly a good idea, but it provides at best very limited reassurance that your app actually doesn't hvae these defects.\n\nAnd that \"all known holes\" in browsers are already closed is likely true where such holes are publicly / widely known, but it doesn't provide reassurance against unknown holes, or holes only known by a small number of people.",
"sig": "b20b2f64a1e366836c3b3021c7cc0688bbcff4ae176ba8cc6dfa70a6ff089d06a62496cf14fc3b4a33c4088b14afd4115e047667020bf334841dd1885535606e"
}