> While WildDuck is more secure by definition than most alternatives
> ...
> You can run WildDuck on any system that supports Node.js,
Node.js and more secure by definition? That sounds _very_ strange to me...
Node.js and more secure by definition? That sounds _very_ strange to me...
* written in memory safe language
* no special permissions needed (besides binding to privileged ports at start but there are workarounds) so no need to be able to chown or spawn workers under different user id's
* no file access for the running daemon, once the daemon starts then it does not read nor write to the local file system
* no spawning shell commands
each of these things is a target for a different attack vector