Is runing node with root safe?

March 14, 2014 1.5k views
I installed node as described in this tutorial. https://www.digitalocean.com/community/articles/how-to-configure-the-nginx-web-server-on-a-virtual-private-server I'm going to let users upload and download. That makes me thing " is it safe to run node as root?"
1 Answer
Hi,


Short answer No...

Long answer
Running anything that uploads or downloads files as root is never a good idea as with root you can do all sorts of nasty things if the js scripts your are running via node are ever exploited. Just a side not when allowing a user to upload files always make sure the files are uploaded into an non-webfacing dictionary as otherwise an exploit could be uploaded and executed very easily.

Hope this helps
Have another answer? Share your knowledge.