Creating an OOB with silverlight is very easy and I think it is a good thing. However, it is also easy to create an application that require higher privilege and with only one click, a user can "allow" the program to do everything on his computer.
Am I correct? Am I correct to feel we are gone back to IE 6's days when executing a harmful activex was so easy?
"Desktop" .Net framework use a Code Access Security to reduce the threat perimeter. Does SL too?