Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But it's the wrong approach.

The correct approach would have been through syscall blocking which is a much lower level.



I'm assuming you mean SELinux style sys call blocking. I think you need both - syscall blocking for the system/deno layer, which enables app layer security in deno itself. That would be the composition-over-inheritance / functional approach.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: