| > But how many C/C++ engineers would think to design a system that runs a min interpreted code Multiple people, in this very thread, including you[0]. And apparently at least one Avast engineer and their upper management. I'll requote/paraphrase another commenter[1] down-thread: it wasn't JS devs who wrote a custom interpreter inside a privileged C/C++ program. It was a C/C++ developer who thought, "I can handle this." It's very important when calling out security failings to point out the real failing. If people are reading this and trying to take away security advice, I don't want their takeaway to be, "so my custom LUA interpreter is fine." [0]: https://news.ycombinator.com/item?id=22545385 [1]: https://news.ycombinator.com/item?id=22545945 |