← Back to context

Comment by HeadOfProbing

9 hours ago

Deno was a good idea in the Old World of software development before LLMs, and simply doesn’t make sense anymore.

Why? We probably need more sandboxing, not less.

Especially with LLMs automating all sorts of code and operational aspects, we could do Tcl/Lua type whitelist sandboxes where the application can only call a limited set of functions.

  • I think it makes more sense to use the kernel‘s’s sandboxing utilities (like seccomp, SELinux, namespaces, prctl and eBPF) than to rely on the process to try to isolate itself purely in userspace which will always have holes.