Hacker News new | past | comments | ask | show | jobs | submit login

It is very interesting although I didn't really understand the 'security' part. The motivation seems to be twofold - some bad things have happened because of compromised npm packages and v8 happens to have a robust sandbox. This sounds like a solution looking for a vaguely defined problem. The illustrative example he gives is 'malicious linter'. Is malicious linter that important a threat?



In the example the linter itself is not malicious, but used to deliver a malicious program that can have unrestricted filesystem access. Not vague at all, see recent news on the ‘event-stream’ package being used to steal cryptocurrency wallets.


The 'vague' part is not that it doesn't happen - see the comment you are replying to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: