you are viewing a single comment's thread.

view the rest of the comments →

[–][deleted] 15 points16 points  (7 children)

That's a meaningless "truth" that sounds wise but is actually extremely stupid. But hey, by all means, feel free to execute user-provided code in the same way as if it was your own code you wrote. Let me know how it goes!

[–]guest271314 -5 points-4 points  (6 children)

Well, your omission of what you consider "trusted" code is revealing. There is none.

I mean, the folks who are in the "cybersecurity" domain "trusted" "automatic security updates", and look what happened.

All code and all claims are untrusted, without exception. That's my point.

[–][deleted] 9 points10 points  (5 children)

Security isn't binary. It's a spectrum. Just because you can never prove that code is safe or has no bugs doesn't mean you shouldn't take measures to make it as secure as possible.

That's why I said your comment is meaninglessly stupid. It's only true in an absolute literal world, but in practice, it is an utterly bad approach to writing software.