Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What I want to know is how many systems does the author of is-positive-integer have implicit root access to?

Sounds to me like publishing oneliners on NPM is a trivial way to build a botnet.



Seems like the answer is "none" by default, from https://docs.npmjs.com/misc/scripts#user

> If npm was invoked with root privileges, then it will change the uid to the user account or uid specified by the user config, which defaults to nobody. Set the unsafe-perm flag to run scripts with root privileges.


That's good, even if nobody is perfectly enough to a botnet. I thought more of the user running the node application.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: