4 ms·
Painting any criticism of deno as simply the work of haters is much more a tactic of stopping thought. Whether or not ideas and discussion are negative or posi
by usea 5y ago
Painting any criticism of deno as simply the work of haters is much more a tactic of stopping thought.
Whether or not ideas and discussion are negative or positive is not relevant at all. When they're presented in some detail and in good faith, we should tackle them in turn. This encourages thought, discussion, and understanding among all.
- skrebbel 5y agoGP's comment is in a thread that starts with "Deno’s permission system is broken, you shouldn’t rely on it". Not relying on Deno's permission system will, in practice, mean just allowing everything or using Node instead of Deno. I can't for the love of god understand why that's better than using a permission system that provides some more protection than just about any other currently-commonly-used backend dev platform. Nobody at Deno is suggesting that their permission system solves all your security risk. I bet "just allow everything" is not what the top poster intended but that's the takeaway. How many Node deployments do you know that use OS-level protections to eg disallow Node from spawning child processes?
- oefrha 5y agoRoot comment literally ended with > If you want to isolate a program, you need to do it on the OS level. Commenter further suggested bubblewrap and firecracker elsewhere in the thread. “Just allow everything” is a straw man you pulled out of nowhere.
- rcxdude 5y agoBecause illusory protection is worse than no protection. if it doesn't actually provide any protection against malicious code in practice then the only thing it can give you is a false sense of security.