Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ecares
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
ecares
4y ago
Ryan: let's use web standards Also Ryan: let's use TSX lol
32.
▲
by
ecares
5y ago
PRs on doc are always appreciated.
33.
▲
by
ecares
5y ago
> Could you not just build a URL loader and cache for importing in Node.js? Could sandboxing not just be a flag in Node.js? Do you really need TypeScript built in? There are open PRs on node for the first two parts ^^ It's 100% doab
34.
▲
by
ecares
5y ago
If I write faulty code, the generated test will make sure I keep the code faulty right?
35.
▲
Node.js/V8 dynamic code injection from outside of the process
(blog.sqreen.com)
16 points
by
ecares
6y ago
|
3 comments
36.
▲
by
ecares
6y ago
So, you mean the people who were supposed to make the best choices to fix server-side JavaScript with the ultimate knowledge of what's best just realized that some of their pre-made opinions are actually not-silver bullet? Shocking
37.
▲
by
ecares
6y ago
At this point, there is clearly a vuln in a tool that brands itself as secure and in opposition with another project. The marketing around Deno has been made toward that and it makes no sense to reach 1.0.0 with such a big security issue un
38.
▲
by
ecares
6y ago
you could use a flag to re-enable http :)
39.
▲
by
ecares
6y ago
Let me tell it another way: browsers have been benefiting from decades of innovation to mitigate the security issues of execution of JavaScript. CORS headers is the latest of theses innovations. Deno allow you to fetch code as a browser wou
40.
▲
by
ecares
6y ago
there are a lot of issues with using a non secure protocol to do anything over the internet, actually someone summarized the issue on the Deno issue tracker. According to them, confidentiality is also a risk. also someone could also send yo
41.
▲
by
ecares
6y ago
Well, diasabling http by default is basically "Internet 101" here. I don't want to write an full lecture on how many attacks are possible when people don't use https. It has been commmon knowledge for way more than a dec
42.
▲
by
ecares
6y ago
Oh, I did not get what you meant ^^ well, there are still other issues than integrity with not using https.
43.
▲
by
ecares
6y ago
>Can checksums/hashes be specified directly in the source file? That would defeat their point actually :D malicious attacker could inject any script by hacking on the network and replace modules that are downloaded through http
44.
▲
by
ecares
6y ago
> Would you say linux is insecure because a user can download an arbitrary shell script and run it? Linux is not branded as a "Secure thing" right? Here Deno is building marketing on something inacurate.
45.
▲
by
ecares
6y ago
well, most of Deno marketing is that it is safe by default. In 2020, not enforcing a secure protocol to share source code is a no go at all. I really don't get your point here defending something that has not made any sence since the
46.
▲
by
ecares
6y ago
btw: https://github.com/denoland/deno/issues/1063 they know there is a bad mitm vector and won't fix it
47.
▲
by
ecares
6y ago
That is not enough at all and there are other attacks! I can't belive in 2020 some people still need to be explained why not enforcing https is a terrible thing! For instance, will a lockfile prevent someone from eavesdropping on the d
48.
▲
by
ecares
6y ago
Well, there is a known MITM vuln in Deno by design and the team refuses to fix it soooooo REF: https://github.com/denoland/deno/issues/1063
49.
▲
by
ecares
6y ago
espacially since https is not enforced! https://github.com/denoland/deno/issues/1063
50.
▲
by
ecares
6y ago
Well is has a huge security hole that ry wont fix https://github.com/denoland/deno/issues/1063
51.
▲
MITM security vulnerability in Deno that maintainer won't fix
(github.com)
4 points
by
ecares
6y ago
|
0 comments
52.
▲
Testing Node.js AsyncLocalStorage in a real life app
(blog.kuzzle.io)
1 points
by
ecares
6y ago
|
0 comments
53.
▲
Finding memory leaks and CPU bottlenecks with Node.js debug tools
(youtube.com)
2 points
by
ecares
6y ago
|
0 comments
54.
▲
by
ecares
7y ago
Right now, a lot of people are layed off because of the COVID crisis. Swith is a platform by the team behind Wanted to help your former employees find a new job ASAP. Definitly the kind of solidarity initiatve we need ATM.
55.
▲
Node.js to provide AsyncLocal-like API
(github.com)
2 points
by
ecares
7y ago
|
0 comments
56.
▲
by
ecares
7y ago
I have not checked them in a while. How do they compare with Github nowadays?
57.
▲
Node.js to support WASM system interface
(github.com)
4 points
by
ecares
7y ago
|
0 comments
58.
▲
Improving V8 Regular Expressions
(v8.dev)
2 points
by
ecares
7y ago
|
0 comments
59.
▲
Building a native add-on for Node.js in 2019
(blog.sqreen.com)
1 points
by
ecares
7y ago
|
0 comments
60.
▲
by
ecares
7y ago
And they wet through YC :D
More ›