3 ms·
People keep casually making this suggestion. In JS this can involve hundreds or thousands of transient dependencies. Have you ever (1) worked on a React app and
by bendmorris 8y ago
People keep casually making this suggestion. In JS this can involve hundreds or thousands of transient dependencies. Have you ever (1) worked on a React app and (2) vetted all of React's 829 dependencies yourself? It's not remotely feasible. The only solution becomes "then don't use React!" - is this the best we can do?
- RSZC 8y agoReact does not have hundreds of dependencies: └─┬ react@16.6.3 ├─┬ loose-envify@1.4.0 │ └── js-tokens@4.0.0 ├── object-assign@4.1.1 ├─┬ prop-types@15.6.2 │ ├── loose-envify@1.4.0 deduped │ └── object-assign@4.1.1 deduped └─┬ scheduler@0.11.2 ├── loose-envify@1.4.0 deduped └── object-assign@4.1.1 deduped
- LeoNatan25 8y agoReact Native then. 1200+ last I remember.
- mannykannot 8y agoThe point, I think, is that this is the real problem, and while Dominic might have made it harder for the attacker to get this exploit into the wild, there is nothing that he could have done that would have prevented such an outcome. If one is writing something as security-critical as a Bitcoin wallet, then not using React (and other things with a similarly wide attack surface) is indeed the best you can do. Security is not tolerant of half-assed measures.