TabFS icon indicating copy to clipboard operation
TabFS copied to clipboard

Security audit, especially of C code?

Open gojomo opened this issue 4 years ago • 1 comments

My main reservation about experimenting with such a powerful & clever thing involves potential security concerns.

Every extension is a little worrisome, but in general open-source plus sufficient-community-of-users plus browser-store-review plus browser-security-boundaries will put me at ease.

But, a custom C-language filesystem, and specifically one that gets pushed JSON data derived from any untrusted website, gives extra pause.

Has the FS code been subjected to any/some/much intense review for security risks? Could it be, on either a volunteer or contracted/crowdfunded basis? Its small size & relative low-rate-of-change even as browser-visible features grow suggest a one-time (or very occasional) bounded effort/cost could offer a long period of peace-of-mind.

gojomo avatar Jan 13 '21 19:01 gojomo

I'd help fund that

jackmac92 avatar Jan 18 '21 01:01 jackmac92