> I think the argument against web-based software is that because you effectively re-download the application on every visit, there are more opportunities for a compromised provider to serve you a malicious version of the application.
Maybe. Lets imagine Google Chrome's update servers were compromised for a day, and the servers hosting a somehow equally popular e2e web based chat app were compromised for a day.
For chrome, it will effect fewer users (most people only update chrome every month, so it only hits 1/30 users). Whereas every user who opened the chat app would be compromised.
The problem on google chrome would be easier to detect, because it wouldn't be able to pinpoint a specific user. Everyone gets the same bad code.
An infected version of chrome would do a lot more damage than a website (because native desktop apps aren't sandboxed at all).
And when the website clears the infection the next day, all infected users of the chat app would have the malicious code removed from their system[1]. But unfortunately, an infected copy of chrome would presumably have its update mechanism stripped out, so it would stay evil much longer. Though maybe this is a wash, because Microsoft and Apple have malicious software detection and removal built into their OSes.
I don't see this as a slam dunk for native software.
> To improve the situation for native applications, it would make sense to use a tamper-evident log like Trillian
This is a fantastic idea. I'd love to see this explored more, and I wonder if we could do something similar some day built into browsers for web apps.
Interestingly it also makes a strong case for apps (like chrome) not having their own binary responsible for updates. Apps on phones are more secure because a malicious binary can't stop itself being removed via Apple / Google's app stores.
And of course, we need better system level application sandboxing in order to reduce the impact of this sort of attack. Its crazy that a malicious binary on my computer can download and modify all data on my computer (owned by any app), and access network shares using my credentials.
[1] I think - there might be ways to prevent this with evil service workers. Does anyone know?