logoalt Hacker News

LoganDarktoday at 6:40 AM3 repliesview on HN

That example classifier is horrendous. A simple substring search for ls/cat/echo/etc?


Replies

chrismarlow9today at 1:21 PM

surely concats of user input, stdout of external dependencies, and non-deterministic output feeding back directly to an eval is safe. it's never been a problem before. not even trying to check the boxes when it comes to security anymore.

Tyr42today at 10:12 AM

Can I do

  echo blah blah >> ~/.ssh/authorized_keys
And that'd be auto approved?
anuramattoday at 8:15 AM

still, far more effective than "NEVER FUCKING GUESS"