logoalt Hacker News

sebiwtoday at 8:37 AM3 repliesview on HN

Which brings us to the old saying: Do not deserialize untrusted data.

In the context of Rubygems and their specs this obviously is harder to manage but dependencies such as Rubygems are and will always be part of your app's Trusted Computing Base.


Replies

sscaryterrytoday at 9:35 AM

> dependencies such as Rubygems are and will always be part of your app's Trusted Computing Base

This mindset is changing, in the npm ecosystem, managing and updating dependencies have become somewhat of a gamble. It is no longer if, its when you are compromised.

show 2 replies
wyagertoday at 10:05 AM

> Do not deserialize untrusted data.

I think the better lesson is "use safe codecs"

ares623today at 10:57 AM

LLMs: hold my beer