|
|
|
|
|
by haack
2221 days ago
|
|
Would you say linux is insecure because a user can download an arbitrary shell script and run it? I know it's not an identical problem, but it does demonstrate that we probably agree that the onus is on the user to assess the risk of any arbitrary code they run on their machine, including the risk associated with the transport they use to obtain that code. Funnily enough I actually agree with you that I would prefer to prevent http imports by default. However doing so won't make importing a library secure, and conversely allowing it doesn't mean it is insecure. As an aside, I noticed you have posted the same one line message about the risk of a MITM attack with http imports 4 times in this thread. You might find it more helpful to contribute to the discussion by explaining why you think that. |
|
Linux is not branded as a "Secure thing" right? Here Deno is building marketing on something inacurate.