|
|
|
|
|
by superkuh
423 days ago
|
|
All of this applies to using your browser and your browser automatically executes code from random sources. If this is your threat model then how are you even posting on HN? Shut down that insecure browser quickly. It is tens of thousands of times more likely to expose your personal data etc etc than nginx. Running nginx isn't madness. Thinking nginx is more of a risk, or even comparable to, your normal daily browser behavior certainly is. Go look up the last nginx RCE. I think you'll be in the 2000s for just bare nginx. |
|
We could go back and forth all day about the likelihood of a v8 sandbox escape vs RCE in a big C program. But another risk to consider is a non-obvious misconfiguration. A default server block with a wildcard server name. A stray symlink inside the docroot. An unexpected mount point. A temporary config change that you forget to revert. So many ways to fail...
Regardless, trusting your entire personal data security to a single layer of protection is madness.
Perhaps only exceeded by the logic of "it hasn't happened for a long time, therefore it will never happen again".
Good luck.