3 ms·
Once again, I ask myself: should we start "shaming" developers who don't use isolation? It still seems I am the exception and most people run their dev environm
by evertheylen 2mo ago
Once again, I ask myself: should we start "shaming" developers who don't use isolation? It still seems I am the exception and most people run their dev environment with full permissions. Why?
I also wrote an article (https://evertheylen.eu/p/shame-devs-without-isolation/ https://evertheylen.eu/p/shame-devs-without-isolation/) to flesh out my thoughts, but I'd be really happy to discuss this in the comments.
- vhcr 2mo agoYes, it gets boring that each time one of these supply chain attack article appears everybody starts talking about cooldowns, 2FA, MFA, etc. Just don't give Node the permissions to your complete filesystem / network.
- acdha 2mo agoI think it’s premature before a lot of tools improve to make that more workable: for example, if you use AWS how realistic is maintain separate IAM for each tool you run and map the right one into a sandbox for each tool? To use your editor’s GitHub integration with a token which can do basic operations and only retrieves a high-privilege token with a hardware presence check when you cut a release? Theoretically you can do it but the friction is enough to make it non-viable.
- evertheylen 2mo agoCould you not use something like https://github.com/superfly/tokenizer https://github.com/superfly/tokenizer for AWS? They list it as an explicit example, but I have little experience with AWS.
- acdha 2mo agoPossibly, but my point was basically that I wouldn’t be judgey about developers not doing something which most tools aren’t designed to make easy, or even possible. We absolutely should be trying to get to the point where it’s easy - this is like software deployment before containers and shouldn’t be.