Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Linux/Unix security model is that different actors are represented by different OS users. When you don't do that, it's already like inviting the burglars in your living room.


Everybody does that. How many untrusted NPM dependencies are installed as we speak? Chrome extensions? Etc.


"Everybody" runs an operating system, where it is common to install programs by downloading random files from the internet and then clicking OK to any UAC prompt. Doesn't mean that this is not insecure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: