Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

most methods of getting persistence involve writing to some config file somewhere. Having your app not have rights to write to any sort of config or code files probably is fairly beneficial.

How much is probably going to depends on how everything is configured, what your threat model is, what service it is, and a million other things.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: