Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
singulasar
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
1.
▲
by
singulasar
6mo ago
https://github.com/betterleaks/betterleaks
2.
▲
by
singulasar
1y ago
Let's hope the defunding of medical research can stop so this can become true
3.
▲
by
singulasar
1y ago
The chalk/debug one https://www.aikido.dev/blog/npm-debug-and-chalk-packages-com... I believe socket also found it this way just a bit later. The dev later said that Charlie notifying him probably shaved off some
4.
▲
by
singulasar
1y ago
Hmm, sure, I can agree that the position is extremist, I still don't agree that 1 (or some) extremist positions makes the current people in power extremist. Or at least, maybe they are, but I think most of the alternatives are more ext
5.
▲
by
singulasar
1y ago
Not really, app sec companies scan npm constantly for updated packages to check for malware. Many attacks get caught that way. e.g. the debug + chalk supply chain attack was caught like this: https://www.aikido.dev/blog/
6.
▲
by
singulasar
1y ago
Again, I disagree, I wouldn't call it extremist. It's vile and wrong, but people all over the political spectrum are in favour of this. there's a difference between something being bad or self-serving, and something being ext
7.
▲
by
singulasar
1y ago
There's multiple security firms by now that constantly scan updated npm packages for malware. Obviously those companies can only do this after a new package has been published. Npm could add this as an automated step during publishing.
8.
▲
by
singulasar
1y ago
or maybe let's not? their actions are clearly not extremist, absolutely not perfect and not always equally democratic, but not extremist or violent like the actual extremists...
9.
▲
by
singulasar
1y ago
on the other hand, the previous supply chain attack was found by automated tech. Also, if MS would be so kind as to just run similar scans at the time a package is updated instead of after the package is updated (which is the only way the a
10.
▲
by
singulasar
1y ago
Yes to the you guys can detect it in my codebase, but it's generally not required for someone to report a compromised package, we do also discover them ourselves quite fast due to automated scans of npm package updates. This is how aik
11.
▲
by
singulasar
1y ago
I'm so sick of people saying this. If you use js for any non-tiny project, you'll have a bunch of packages. Due to how modules work in js, you'll have many, many sub dependencies. Nobody has time to review every package they&
12.
▲
by
singulasar
1y ago
https://circleid.com/posts/chat-control-proposal-advances-de... https://fightchatcontrol.eu/ https://european-pirateparty.eu/chatcontrol-eu-ministers-wan...
13.
▲
by
singulasar
1y ago
unphishable 2fa would have prevented this specific case tho... what are you talking about?
14.
▲
by
singulasar
1y ago
the company that first found this vulnerability also has a tool for this https://www.npmjs.com/package/@aikidosec/safe-chain
15.
▲
by
singulasar
1y ago
I think it's quite good, there's a sense of urgency, but it's also not "immediately change it!" they gave more than a day, and stated that it would be a temporary lock. Feel like this one really hit the spot on that