3 ms·
Missile defense systems are unnecessary because they could just use tanks Anti-tank measures are unnecessary because they can just use missiles
by lkjdsklf 2mo ago
Missile defense systems are unnecessary because they could just use tanks
Anti-tank measures are unnecessary because they can just use missiles
- rcxdude 2mo agoWhat's your solution to using a library without executing the code in it?
- msm_ 2mo agoThis is moving the goalposts. The original problem was that installing a library should not execute code from that library. In most sane environments, like for example native languages, this is already the case. Downloading a .dll file and putting it in an appropriate directory won't, by itself, execute code in that library. You may argue that the code will get executed at some point anyway, but that's besides the point. Sandboxing the build environment is a different problem than sandboxing the test/staging/production environment. I think we both agree that "adding random obstacles that don't actually protect anything" is not a valid approach to security, but my mental model of the build step is "transformation of input data into output data", and while this step may produce a malicious output from malicious inputs, it should not do anything malicious itself. For example, "gcc source.c" should not execute arbitrary code by itself.
- rcxdude 2mo ago>In most sane environments, like for example native languages, this is already the case. Installing a node package is much more like compiling a dll, not downloading it. The same is true for most package managers that exist for C and C++ as languages as opposed to for an OS. These are two different tools for different use-cases. (though still pretty much all installation processes for all OSs involve an opportunity for arbitrary code execution, as well, apart from just downloading a zip file and extracting it, which is not the norm)