Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not just memory footprint (which is still at least somewhat relevant, and if you've never tried to delete a node_modules folder from Windows explorer you're in for a treat. More Microsoft's fault, but still annoying), but the sheer amount of trust required for all the dependencies. Only one of those tons of dependencies needs to be subverted to do something awful to you. The attack surface is much larger than it is in other environments.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: