Remix.run Logo
paxys 8 months ago

> But having it is generally better than not having it.

So is HN and every other site in the world insecure because it allows users to post "/etc/hosts" ?

8 months ago | parent | next [-]
[deleted]
8 months ago | parent | prev | next [-]
[deleted]
mystifyingpoi 8 months ago | parent | prev [-]

Maybe? I don't know nor care. Assuming that HN has a vuln with path traversal, a sanely configured WAF would block the traversal attempt.

latexr 8 months ago | parent | next [-]

I propose someone who doesn’t know or care how a system works shouldn’t be prescribing what to do to make it secure. Otherwise this is like suggesting every gate must have a lock to be secure, even those which aren’t connected to any walls.

https://i.imgur.com/ntYUQB1.jpeg

MatthiasPortzel 8 months ago | parent [-]

> someone who doesn’t know or care how a system works shouldn’t be prescribing what to do to make it secure

The part that’s not said outloud is that a lot of “computer security” people aren’t concerned with understanding the system. If they were, they’d be engineers. They’re trying to secure it without understanding it.

saagarjha 8 months ago | parent [-]

Good computer security people are engineers.

smallnix 8 months ago | parent | prev [-]

*some traversal attempts