Hacker News new | past | comments | ask | show | jobs | submit login

I know "code is data", but it's a couple orders of magnitude more reasonable to have unsafe bytecode than to have unsafe data deserialization.

If something is supposed to load arbitrary code, not just data, that needs to be super clear at a glance. If it comes across as a data library, but allows takeover, you have a problem. Especially if there isn't a similar data-only function/library.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: