57
submitted 19 hours ago by SorteKanin@feddit.dk to c/rust@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] protogen420 3 points 17 hours ago

make RCE a second class feature instead

[-] LPThinker@lemmy.world 2 points 16 hours ago

What RCE are you talking about?

[-] protogen420 4 points 12 hours ago

wasm and js are by definition remote code execution

"oh but is sandboxed" how many sandbox bypass and sanbox escape CVEs have we had? incountably many

beyond that, that is code using your cpu cycles often inefficiently and for useless purposes or outright malicious purposes such as tracking

[-] ISO@lemmy.zip 1 points 1 hour ago* (last edited 1 hour ago)

Let's take Lemmy UIs as an example. In a world where this "RCE" is removed, all API calls and returned data would have to go through a "server client" first. I hope this won't take you long to ponder if that's an improvement or not ๐Ÿ˜‰

The web is indeed shit. But dumber web means more "clouding", or if it's not "clouding", and to borrow from your reductionist fatalism: Dumber web replaces a potential RCE with a definite MITM.

[-] Ephera@lemmy.ml 2 points 12 hours ago

I'm guessing, they mean JavaScript and WebAssembly in general...

[-] rtxn@lemmy.world 2 points 14 hours ago

All the RCE vulnerabilities that Apple introduced as "features"

this post was submitted on 27 Feb 2026
57 points (100.0% liked)

Rust

7816 readers
71 users here now

Welcome to the Rust community! This is a place to discuss about the Rust programming language.

Wormhole

!performance@programming.dev

Credits

  • The icon is a modified version of the official rust logo (changing the colors to a gradient and black background)

founded 2 years ago
MODERATORS