11 ms·
I think a better solution would be to never execute anything unsandboxed.
by malka 5y ago
I think a better solution would be to never execute anything unsandboxed.
- tracker1 5y agoMy initial thoughts as well.. have been playing with development inside containers, and this just makes me sure I need to do it much more. Also, pushing for read-only containers in production for most things, along with running as a non-privileged user.
- hda2 5y agoUnless your program is a black box that doesn't interact with the rest of the world in any way, sandboxing will not be enough. People still need to mitigate the effects of malicious supply chains.
- yurish 5y agoThis may protect your computer, but not visitors of your site using malware npm module on front end.
- malka 5y agothat is the job of browser vendor to sandbox on the front-end side