Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

We've seen countless examples of relatively minor libraries being exploited which then cause havoc because of a spider web of transitive dependencies.


On Qubes OS (my daily driver), which runs everrything in VMs with strong, hardware virtualization, you can use minimal operating systems with very low number of installed libraries for security-critical actions: https://www.qubes-os.org/doc/templates/minimal/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: