10 ms·
Anybody who doesn't use a dev VM these days is asking for trouble. It's too easy for attackers to run malicious code on your machine with techniques like this.
by Techies4Trump 6y ago
Anybody who doesn't use a dev VM these days is asking for trouble. It's too easy for attackers to run malicious code on your machine with techniques like this.
- riyakhanna1983 6y agoNot only that, you could end up shipping malicious code to your customer.
- ajsharp 6y agoHow would a dev vm prevent this? Vms can still call out to the internet.
- badrabbit 6y agoNo host FS or clipboard access means it would be rendered useless.
- justinclift 6y agoHmmm, that depends on the virtualisation solution being used. If someone's using (say) VMware Workstation or Fusion, if they've loaded the VMware tools into the VM it can share the clipboard and be configured with access to the hosts filesystem (at defined points).
- badrabbit 6y agoIf you set it up that way it will. If you are doing this intentionally then just don't set it up that way.
- _eht 6y agoI would go as far as saying anyone who does not have control and awareness of their dependencies is asking for trouble. VM be damned.
- akira2501 6y agoThat's part of the reason I feel uncomfortable with "modern" package systems like golang's. I really want to use golang more, but I just don't feel 'secure' about building a bunch of packages pulled off of github by URL.
- _eht 6y agoThird-party package management is not a modern marvel by any means. You are unnecessarily singling out golang, and if you let that stop you from learning it's your loss. Just be smart. Dependency awareness is not black magic.
- jatone 6y agoodd golang has a better security story than npm, rubygems, and python. it'll at least crypto ensures the dependency code hasnt been modified since you first retrieved it iirc. the rest is up to you as a developer to ensure its safe.
- deleted 6y ago[deleted]