When I see things like the react server exploit I can’t help but think, like… why put in all of the effort to make something so overly complex that it has such large of an attack surface? Like, I know this is uncharitable and that there are reasons why security is hard, but this is also JavaScript. It’s a memory safe language. It really only misbehaves when you let it.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.treehouse.systems/users/jnkrtech/statuses/115658744712165980 on your instance and quote it. (Note that quoting is not supported in Mastodon.)