4 ms·
using deno isn't good security practice, their sandbox is implemented like stuff from the 90s
by bugtodiffer 1y ago
using deno isn't good security practice, their sandbox is implemented like stuff from the 90s
- bflesch 1y agoIs node "sandbox" different? Does it even have a sandbox?
- throwitaway1123 1y agoNode does have a permissions system, but it's opt in. Many runtimes/interpreters either have no sandbox at all, or they're opt in, which is why Deno's sandbox is an upgrade, even if it's not as hardened as iptables or Linux namespaces.
- homebrewer 1y agoIf you're writing server stuff, at the coarse-grained level of isolation that Deno provides you're better off using just about anything else and restricting access to network/disks/etc through systemd. Unlike Deno, it can restrict access to specific filesystem paths and network addresses (whitelist/blacklist, your choice), and you're not locked into using just Deno and not forced to write JS/TS. See `man systemd.exec`, `systemd-analyze security`, https://wiki.archlinux.org/title/Systemd/Sandboxing https://wiki.archlinux.org/title/Systemd/Sandboxing
- crabmusket 1y agoDeno can restrict access to filesystem files or directories, and to particular network domains, see docs for examples. https://docs.deno.com/runtime/fundamentals/security/#file-system-access https://docs.deno.com/runtime/fundamentals/security/#file-sy... However in general I don't think Deno's permission system is all that amazing, and I am annoyed that people call it "capability-based" sometimes (I don't know if this came from the Deno team ever or just misinformed third parties). I do like that "deno run https://example.com/arbitrary.js https://example.com/arbitrary.js" has a minimum level of security by default, and I can e.g. restrict it to read and write my current working dir. It's just less helpful for combining components of varying trust levels into a single application.
- bugtodiffer 1y agoYes it says it can do it, but it has been broken many times because it is shit
- vorticalbox 1y ago> Unlike Deno, it can restrict access to specific filesystem paths and network addresses deno can do this via --(allow/deny)-read and --(allow/deny)-write for the file system. You can do the same for net too https://docs.deno.com/runtime/fundamentals/security/#permissions https://docs.deno.com/runtime/fundamentals/security/#permiss...
- mk12 1y agoBubblewrap is another convenient sandboxing tool for Linux: https://wiki.archlinux.org/title/Bubblewrap https://wiki.archlinux.org/title/Bubblewrap
- oblio 1y agoCan you expand on this please? Also curious which 90s tech there inspired by.
- bugtodiffer 1y agoIt is matching strings instead of actually blocking things. That's how sandboxes were implemented when I was a kid. E.g. --allow-net --deny-net=1.1.1.1 You cannot fetch "http://1.1.1.1 http://1.1.1.1" but any domain that resolves to 1.1.1.1 is a bypass... It's crap security
- jeltz 1y agoThat isn't 90s security, that is just bad code. And bad code was written in the 90s and is still written today.
- whizzter 1y agoIf security principles are important they should be on a deny-default basis with allow-lists rather than the other way around. If the deno runtime implements the fetch module itself, then post-resolution checking definitely should be done though. It's more of an bug though than a principled security lapse.
- bugtodiffer 1y agoThe thing is that this applies to all parts of the sandbox https://secfault-security.com/blog/deno.html https://secfault-security.com/blog/deno.html
- oblio 1y agoAh, so by default it's default deny everything but once you need to open up categories, you can't just allow exact what you need in that category? You have to allow the entire category and then deny everything you don't want/need? That's a bit of a silly model.
- throwitaway1123 1y ago