news.volyx.in

A proposal to restrict sites from accessing a users’ local network (github.com)

680 points by doener · 421 days ago · 376 comments on HN

Article summary

A proposal aims to restrict websites from accessing a user's local network without permission. This change could affect various use cases, including password managers and local device management. The proposal replaces the previous Private Network Access specification. The goal is to improve security and privacy by limiting unwanted access to local networks.

Main themes

  • local network access
  • security and privacy
  • device management
  • password managers
  • cloud services
  • self-sufficiency
  • browser security
  • OS security
  • permission systems
  • PaaS and Google's goals

What commenters say

  • Restricting local network access will help prevent malicious activities, such as sneaking identification code sharing between native apps and websites.
  • The proposed restriction will break existing solutions and cause inconvenience for legitimate use cases, such as local device management and password managers.
  • Allowing websites to access local networks without permission is a security nightmare and should be stopped.
  • Some commenters argue that the restriction is unnecessary and that existing solutions, such as HTTPS and Let's Encrypt, can provide sufficient security.
  • Others believe that the restriction will promote self-sufficiency and reduce reliance on cloud services.
  • The proposal may be self-serving for Google and promote their PaaS goals.
  • Some argue that the OS should be responsible for securing running applications, rather than the browser.
  • A permission prompt system could be implemented to allow users to control which websites can access their local network.