Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's fish. What's insecure about the way I'm using it?


/tmp is world-writable. Any local user could create /tmp/fuckgit and stuff it with malicous code.


Or create /tmp/fuckgit as a symbolic link beforehand, pointing to a directory which will be deleted by the first command in your function.


I see, thank you.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: