3 ms·
> That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways? I won't ex
by ashishb 1y ago
> That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways?
I won't execute that code directly on my machine.
I will always execute it inside the Docker container.
Why do you want to run commands like `vite` or `eslint` directly on your machine? Why do they need access to anything outside the current directory?
- bandrami 1y agoI get this but then in practice the only actually valuable stuff on my computer is... the code and data in my dev containers. Everything else I can download off the Internet for free at any time.
- ashishb 1y agoNo. Most valuable data on your system for a malware author is login cookies and saved auth tokens of various services.
- hinkley 1y agoMaybe keylogging for online services. But it is true that work and personal machines have different threat vectors.
- spicybright 1y agoYes, but I'm willing to bet most workers don't follow strict digital life hygiene and cross contaminate all the time.
- kolme 1y agoYou don't have any stored passwords? Any private keys in your `.ssh/`? DB credentials in some config files? And the list goes on and on.
- bandrami 1y agoI don't store passwords (that always struck me as defeating the purpose) and my SSH keys are encrypted.
- jamesnorden 1y agoThis kind of mentality, and "seems a bit excessive to sandbox a command that really just downloads arbitrary code", is why the JS ecosystem is so prone to credential theft. It's actually insane to read stuff like that said out loud.
- bandrami 1y agoRight but the opposite mentality winds up putting so much of the eggs in the basket of the container that it defeats a lot of the purpose of the container.
- apsurd 1y agoit annoys me that people fully automate things like type checkers and linting into post commit or worse entirely outsourced to CI. Because it means the hygiene is thrown over the fence in a post commit manner. AI makes this worse because they also run them "over the fence". However you run it, i want a human to hold accountability for the mainline committed code.
- throwaway290 1y agoIt's weird that it's downvoted because this is the way
- apsurd 1y agomaybe i'm misunderstanding the "why run anything on my machine" part. is the container on the machine? isn't that running things on your machine? is he just saying always run your code in a container?
- minitech 1y ago> is the container on the machine? > is he just saying always run your code in a container? yes > isn't that running things on your machine? in this context where they're explicitly contrasted, it isn't running things "directly on my machine"