4 ms·
Most programmers and power users install large dependency trees with npm/pip/bundler/... on the same user account as their main browser on a regular basis. Even
by progval 3mo ago
Most programmers and power users install large dependency trees with npm/pip/bundler/... on the same user account as their main browser on a regular basis. Even on Linux where it's easy to create new user accounts. This isn't much different.
- shaky-carrousel 3mo agoMost programmers use docker or don't install extensions unapproved by their company.
- iamflimflam1 3mo agoI think you should clarify that with “most programmers I work with”.
- shuwix 3mo agoHe should clarify that "most" can be easily replaced by "all" as it was determined by statistical pool of whopping 1 person - himself. And also clarify that it's all lie. He just want to tell the anonymous crowd "look, I'm better than you".
- shaky-carrousel 3mo agoYou should also clarify that you pulled your statements out of your butt to look edgy. Everyone in every team I worked for the last ten years use docker. Docker is old tech. If you and your cavemen devs ignore what it is, that's your problem.
- _joel 3mo agoDocker is old tech, yes, doesn't mean every dev in the world uses it. They don't. Jails/zones are even older (hell a chroot). Did developers all use those before due to them being 'old tech'. No.
- shaky-carrousel 3mo agoAny reasonably big project uses docker because it's a very simple way to have the exact environment in both production and in dev. Also it is helpful for keeping things isolated. In all projects I've worked for the las ten years for several major companies, docker has been a requirement.
- _joel 3mo agoI'm aware of what docker is, I've been using it myself since it's inception and the tech I listed even before that. I'd recommend not assuming everything you have seen applies everywhere, to everyone else. "Just 30% of developers say they use containers in any part of their workflow." https://www.docker.com/blog/2025-docker-state-of-app-dev/ https://www.docker.com/blog/2025-docker-state-of-app-dev/ So, yea. Large companies, yes, for sure. But that's not 100% - is it.
- shuwix 3mo ago[flagged]
- kelnos 3mo agoI don't think the GP said anything about their own practices, just their impression of the majority of devs. Maybe turn down the temperature on your vitriol a bit?
- snovymgodym 3mo agoSure, modern containerization is objectively good and should be used pretty much everywhere unless you have a strong reason not to, but the unfortunate reality is that it is nowhere near as universal as it should be.
- Izmaki 3mo agoIn my experience more than 9/10 programmers I've worked with have never used Docker before and of those who have, the majority have never used Docker for anything personal. If I hand them an image for a Dev Container, sure, they might use it, but it becomes "a thing we need to do, to compile our code in our IDE" not a tool they would use for isolation*. *) OP seemed to imply that containerization would be nice for safety and security compared to bare metal, but containers were never built for isolation in the first place, mind you. They are namespaces and chicken-coop-like-jails at best.
- avadodin 3mo agoI don't use them in the way the heavy docker users use them but I have been using docker and even earlier Linux on Linux container solutions for decades. There was some user chroot thing early on that required me to make a library to intercept the setuid calls to pretend the garbage root-only build system was running as root on everyone else's lowly user account. And that's not even including the myriad of distroboxes I need to do anything at all on my gaming pc.
- _joel 3mo agoThat's patently not true, source, me, a DevOps manager who has had to roll out proper docker and security policy for devs for the past 10 years :)
- kelnos 3mo agoYour anecdote does not make GP's comment "patently untrue". It's just a counter-example, and we don't know how prevalent your scenario is compared to GP's. (And I agree with the GP. I'm fairly cynical about most developers' security stance and threat model. Source: my own usage patterns.)
- _joel 3mo ago"Just 30% of developers say they use containers in any part of their workflow." https://www.docker.com/blog/2025-docker-state-of-app-dev/ https://www.docker.com/blog/2025-docker-state-of-app-dev/ I welcome your apology.
- fluffybucktsnek 3mo agoWhy should they apologize? All they did was point out that you just provided a counter example, not statistics (thus "we don't know how prevalently your scenario is" yet), and share a personal opinion. No accusations were made.
- XorNot 3mo agoIt has never been easy to create separate users on Linux, certainly not for tasks where you need to switch between contexts. Docker was amongst the biggest steps forward on this in a long time.
- deleted 3mo ago[deleted]
- progval 3mo agoI meant for CLI tasks. Just "adduser" and "sudo -u <user> bash".
- brookst 3mo agoAnd when you want to share some but not all files with that one user but not other users you created for similar purposes? And when you want the outputs of that user back to your main user? And when you want that user to access some shared credentials for external services, but not all? It’s not the account setup that’s hard, it’s the workflow of spreading a single real-world across multiple accounts.
- gumby 3mo agoThat’s what user groups are for.
- deleted 3mo ago[deleted]
- seanhunter 3mo agoAll of those use cases are very easy to facilitate using filesystem permissions and groups.
- brookst 3mo agoAnd you set up these permissions and groups for each individual task to be done? Do you tear them down after the task? Or maintain a lot of them for “LLM helps with house renovation” versus “LLM helps plan travel”?
- chrisandchris 3mo agoTwo bads doesn't give you one good.
- reactordev 3mo agono, but it does give one multiple vectors for exfiltration of your data which is a good thing for the scammers of the internet. A bad thing if you naively designed your package management system. Sadly, it's only going to get worse.
- brookst 3mo agoNo, but when you’re arguing that common practices followed by pretty much everyone is “bad”, it’s hard to muster much urgency. Yeah, we should do this differently. We should probably also eat healthier and get to the gym more.
- port11 3mo agoRunning LLMs with some form of sandboxing is much easier than eating healthy or going to gym. Speaking as someone that is procrastinating lifting weights but found 15 minutes to lock down Claude.
- idiotsecant 3mo agoTwo bads does eliminate the option for smugness though
- Henchman21 3mo agoPfft, not on HN.
- cowpig 3mo agoIt's much different. The dependency trees have a whole system that's evolved for decades. The same code goes into many computers. Many people read the source, security firms look for vulnerabilities, etc. Language models are a completely new paradigm. The code it writes on your machine is the only instance of that code. It does far more than anybody could ever keep track of. It's much harder to detect problems, and nobody to hold accountable for them.
- SubiculumCode 3mo agoIs there a general workflow for this? I usually do pip under my user. I had not thought to do a su then do my venv and pip. Heck, are we at the point where we shouldn't even do that and everything should be done in a vm container?
- tga_d 3mo ago> Heck, are we at the point where we shouldn't even do that and everything should be done in a vm container? This is the premise of Qubes OS. It's gotten decently usable, I'd estimate about as good as Linux a decade ago. https://www.qubes-os.org/ https://www.qubes-os.org/
- processunknown 3mo ago+1 for qubes. with some effort you can get a really nice stack with segmented git, disposable coding agents, package cachers, firewalls, and network visibility.
- neop1x 3mo agoIt's easy but very inconvenient. Drop sandbox [1] or Docker are much more convenient alternatives to user/group isolation for this purpose. [1] https://github.com/wrr/drop https://github.com/wrr/drop