Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks for the clarification.

> I lol'ed.

Then I don't understand their choice. I know there are many java devs, but I think delivering an API through java shields from many attack vectors.

I know java has its vulnerabilities, but it's easier to cover those than to design an OS which is secure from a C/C++ point of view.

Using old techs that are being used by many devs has many advantages, one is that security problems won't be new.

And to be clear: I hate java.

> There is no correlation here.

I was just saying it's better to march into known territory which are existing techs, than to create new techs in which you don't know who will find an exploit first: the white hat or the black hat. Existing techs are like old guys you can trust because they've been here for a long time. I guess the sandboxing is very nicely done, but a tech is not mature until it's not a very little bit used in a mainstream fashion, so that security people can look its parts more closely.

I'm not a security expert anyways, I'd love to watch NaCL be used more, but computer security will always make things suck one way or another.



The sole reason for basing Android on Java was its popularity, which grant it good tools and familiarity. The creators said as much several times.


"And to be clear: I hate java."

Most people probably like JVM rather than Java.


The JVM contains decades worth of knowledge, some of which was developed for languages like Self.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: