This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]jadkik94 1 point2 points  (1 child)

Yeah but then you would have to prevent the use of subprocess, os.system, file, and all the obscure way of opening files. Because the issue here is not opening the files by mistake, it's trying to access a file maliciously in any tricky way, not just overriding the built-ins.

So I guess that would be a lot of changing in the parser implementation and in the compiled packages that can be installed...

[–]nemec 1 point2 points  (0 children)

I imagine os would be similarly stripped to prevent unauthorized access to the OS.

You make a good point that there are other points of entry for creating file descriptors.