Comment on Observability Stack?
nykula@piefed.social 1 week agoWhat’s insecure about CGI? I thought the main reason it isn’t popular now is because runtimes are slow to start. Though IIRC when I used busybox httpd CGI with a small runtime, quickjs, speed wasn’t an issue.
non_burglar@lemmy.world 1 week ago
From a security perspective, it’s a big mess of inputs and can have really inappropriate access to local filesystem on the web server unless you really know what you’re doing. Combine that with Perl (also a pita to secure), and it’s now a liability.
These are good tech, I used them a lot myself. But the structure of a language and how it builds things is important too, and that’s why very few ppl bother with Perl or CGI now (besides them also being fails on certain security audits.)