I agree that the developer has to check that the code doesn'...

inkan

npub16xnpfx85k8wzdhctang6860g3u64lds5kac73ddjwlg0lxdg9g3su56z6l

hex

9ef112b69109acc84f5a26ebddbd9baf7d29bfeed8feee4248812a6e85b952d2

nevent

nevent1qqsfaugjk6gsntxgfadzd67ahkd67lffhlhd3lhwgfygz2nwsku495sprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsdrfs5nr6trhpxmu97e5dra85g7d2lkc2twu0gkke8058lnx5z5gcg8u0fe

Kind-1 (TextNote)

2026-09-07T03:04:03Z

↳ 回复 事件不存在

bf5fde8b9748537a75db369280f7f6ff060223955c69d8b2648e83bd92430350...

I agree that the developer has to check that the code doesn't leak or give access to secrets, but I don't think that developers should have confidence that they were in any particular case able to do so successfully.

Also, repeatedly asking an AI that there is no remote code running within an app and that nothing is leaked outside the browsers runtime is certainly a good idea, but it provides at best very limited reassurance that your app actually doesn't hvae these defects.

And that "all known holes" in browsers are already closed is likely true where such holes are publicly / widely known, but it doesn't provide reassurance against unknown holes, or holes only known by a small number of people.

原始 JSON

{
  "kind": 1,
  "id": "9ef112b69109acc84f5a26ebddbd9baf7d29bfeed8feee4248812a6e85b952d2",
  "pubkey": "d1a61498f4b1dc26df0becd1a3e9e88f355fb614b771e8b5b277d0ff99a82a23",
  "created_at": 1788750243,
  "tags": [
    [
      "e",
      "71548e70da7ec315931758f97acf0006df89cfae4fff8245142b5dcb522dd9a8",
      "wss://basspistol.org/",
      "root",
      "3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
    ],
    [
      "e",
      "bf5fde8b9748537a75db369280f7f6ff060223955c69d8b2648e83bd92430350",
      "wss://relay.primal.net/",
      "reply",
      "5538e28a66eb88360f15f8fa95646bdd2daa2999aacfe4faacf43d0c0540b281"
    ],
    [
      "p",
      "3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
    ],
    [
      "p",
      "efc2b6e59480f0e55cc87c69af06b6d1a11fa25e4ea95a439878c41799c53c19"
    ],
    [
      "p",
      "5538e28a66eb88360f15f8fa95646bdd2daa2999aacfe4faacf43d0c0540b281"
    ]
  ],
  "content": "I agree that the developer has to check that the code doesn't leak or give access to secrets, but I don't think that developers should have confidence that they were in any particular case able to do so successfully.\n\nAlso, repeatedly asking an AI that there is no remote code running within an app and that nothing is leaked outside the browsers runtime is certainly a good idea, but it provides at best very limited reassurance that your app actually doesn't hvae these defects.\n\nAnd that \"all known holes\" in browsers are already closed is likely true where such holes are publicly / widely known, but it doesn't provide reassurance against unknown holes, or holes only known by a small number of people.",
  "sig": "b20b2f64a1e366836c3b3021c7cc0688bbcff4ae176ba8cc6dfa70a6ff089d06a62496cf14fc3b4a33c4088b14afd4115e047667020bf334841dd1885535606e"
}