Skip to content

Comment on Can we get the benefits of transitive dependencies without undermining security?parent

Comments

Capabilities taken literally are more of a network thing (it's how you prove you have access to a computer that doesn't trust you). On a language, you don't need the capabilities themselves.

You may be thinking of the term in a different context. In this context, they are a general security concept and definitely apply to more than the network, including languages:

https://en.wikipedia.org/wiki/Capability-based_security

http://habitatchronicles.com/2017/05/what-are-capabilities/ (this is a great article)

https://www.ponylang.io/

etc...

On a language, you don't need the capabilities themselves.

Why not? Sometimes I want that. Just today I was looking at some code and realized that it was being used by groups that shouldn't. The code needs to be there and is great for the correct users, but someone is going around our architecture and we didn't notice it.

You are replying to the wrong post. I was quoting the GP.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.