Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This reminds me somewhat of OLE, COM, DCOM, ActiveX, ... [1]. You can paste an Excel chart into a Word document and if you update the data in Excel, the chart in Word will update. You can edit the chart in Word using the Excel UI because you are essentially running an Excel instance inside of Word. You can interact with Excel through an API, no need for a human. But it is painful, you can probably imagine the kind of API you need in order to be able to do all the things you can do with the Excel UI.

The idea is amazing, making this work consistently requires effort, and a lot of it. And as only a few applications invested this effort, it only works with a few applications and never really took off outside of Microsoft. I think this used to work with WordPad and maybe even Notepad but it no longer does, you just get an image instead of the chart object in WordPad and nothing at all in Notepad. It is a dying technology.

[1] https://en.wikipedia.org/wiki/Component_Object_Model



At least there's no history of security issues with that.


Can you explain how the COM/ActiveX security history applies here?


I had a similar wincing reaction to the expressed idea of wanting to converge output, control, and interaction under a terminal muxer in today's wacky world.

But that's because today's world is forcing us towards overwhelming risk management and compliance systems like NIST 800-53 and friends. If anything, these mechanisms are being drawn, quartered, and spread to the opposite corners of the Earth.

Control via configuration management systems with configuration drift detection etc. Outputs and diagnostics via monitoring, logging, audit, and accountability systems. Authorization systems with extreme least privilege, draconian rules for privileged role assumption. Interaction removed from the entire operations plane, so it only exists in some application domain concepts as a sort of ship in a bottle, which eventually perversely recurses into the same mindset for domains with interesting content and user roles.

Lots of access path restrictions intentionally limiting which usage scenario is available in which combination to which user type from which locale with which client device.

So the idea of flexible and convenient fusion of many different IO and control paths into a portable and remotely attachable terminal UX seems like the complete antithesis..?


Or such a fusion will be in the next release of systemd…


The specific technology causes security issues? Nope.

The Visual Basic empowers a whole generation of non-coders to become sort of coders causes security issues? Yeah, I think I can do that with AI.


They can at least deliver baseline value, because it's all text-based. Do agree that it'll become more complex, when/if they decide to create custom protocols.


I think you may have meant to comment on another post :)


No, correct post. But maybe I am misunderstanding the idea behind the post, that is certainly possible.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: