Hacker News new | ask | show | jobs
by zasdffaa 1329 days ago
And a turing complete language delivered from a third party over said network connection to be executed locally will exponentially increases that risk, no?

> JavaScriot runtimes are quite well audited meanwhile.

Given (for example) the leftpad trainwreck, is that really true?

1 comments

> > JavaScriot runtimes are quite well audited meanwhile.

> Given (for example) the leftpad trainwreck, is that really true?

That was that some (quite pointless) code was not available anymore as easily. Not a security issue.

That's entirely irrelevant. It was available, got used, and things massively fell over when it was pulled. You've given no case to show things have changed - can you actually give any evidence that 'JavaScriot runtimes are quite well audited'.
Correct, leftpad ia completely irrelevant for the discussion.
And helloooo eternal september. You haven't a clue.
It really was a non-event.