Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The next step is to utterly forbid "installers" and make everything work this way, and to add stronger privilege isolation and organized APIs for apps to talk to each other.

I agree and disagree with you. I would be awesome if I could restrict apps and forbid installers. I'd also like to be able to run arbitrary apps as forbidden to use the internet and make them think they are reading/writing to /some/path/ but they are really reading/writing to /app/sandbox/some/path. I'd love the option.

But then there are problems with that as well. Want to make an app plugin? Nope. Want to share libraries? Nope. Want to talk to an app? Hope it's got a canonical port number.

So I don't think enforcing boundaries is the way to go. I'd love to see other opinions and whether or not there are any alternatives, though.



I think there are creative solutions to this. Like I said: there would need to be a well-designed inter-app API.

Plugins for instance could be handled like firmware updates to a device. Send the image to the app via the API. "Here is your plugin..." Or some apps could have their own plugin stores, ala the Chrome store. There are different ways of handling this.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: