Live data from Hacker News

Viewing profile — louislang

louislang

HN member
Joined
Mon, Sep 26, 2022, 9:19 PM UTC
HN karma
1,263
Public activity
126 items

About louislang

Co-founder @ phylum.io

louis@lang.sh

[ my public key: https://keybase.io/louislang; my proof: https://keybase.io/louislang/sigs/sR5R808tt65aCugytdt6xz-in9aUoyyvTGAKLTYe1gI ]

Recent public activity

  1. comment
    Comment #41342224

    DARPA is doing something similar to this with their TRACTOR work. https://www.darpa.mil/program/translating-all-c-to-rust

  2. comment
    Comment #41182947

    (Full disclosure: I'm one of the co-founders @ Phylum) We could do a full write-up on npm's quirks and how one could take advantage of them to hide intent. Consider the following f…

  3. story
  4. story
  5. story
  6. story
  7. comment
    Comment #39857753

    this is still true of node/npm. It's also true of Cargo (Rust), Nuget (C#), and a handful of others. I'd say it's probably the _norm_ for most ecosystems to allow some form of pre/…

  8. comment
    Comment #39857633

    I'm one of the co-founders @ Phylum. We've been tracking this campaign [1] (along with several other unrelated ones). The collective group of security researchers (Shoutout to http…

  9. comment
    Comment #39857074

    Yeah, the broad campaign makes it extremely noticeable. There are active campaigns right now that don't take this approach. Singular packages with novel malicious payloads. > As a …

  10. comment
    Comment #39856865

    No, this is not unique to Python or PyPI. I'm one of the co-founders @ Phylum. We've tracked campaigns across Crates.io, Nuget, npm, PyPi, etc. see: https://blog.phylum.io/tag/rese…

  11. story
  12. comment
    Comment #38836670

    Seems like gaming tax makes up for the loss of personal income tax.

  13. comment
    Comment #38646940

    Yeah, 1.1.[5,6,7] were involved in the attack.

  14. comment
    Comment #38646863

    Co-founder @ Phylum here ( https://phylum.io ). We've been actively scanning dependencies across most open source package registries (e.g., npm, PyPI, Crates.io, etc.) for a few ye…

  15. comment
    Comment #38284628

    People approach things through a lens of familiarity. Programmers are likely relating it to their experience.

  16. story
  17. comment
    Comment #37442638

    One of the sources referenced in the paper is about the work the company I co-founded is doing ( https://phylum.io ). We've been working closely with PyPI to not only report issues…

  18. comment
    Comment #37411939

    What makes you say that? There doesn't seem to be a ton of info on that page about _what_ it is. Certainly not enough to call it an after though.

  19. comment
    Comment #37387748

    The fact that I'm in Houston and have grown accustomed to the threat of yearly hurricanes is personally alarming.

  20. comment
    Comment #37346286

    Happy to see this on HN! I'm one of the co-founders @ Phylum. We actively monitor and report on malware and software supply chain attacks across multiple ecosystems. Most notably, …

  21. comment
    Comment #37346173

    Sorry, I just saw this! We actively monitor each open source repository and as packages are published, we pull them down and analyze each line of code and any associated metadata. …

  22. comment
    Comment #37267258

    It's some stupid blog setting. I just disabled it. Thanks for the heads up!

  23. comment
    Comment #37265897

    Response time was one of the best we've experienced at Phylum. It's obvious you guys are putting in a ton of work over there. Please let me know if there's anything we can help out…

  24. comment
    Comment #37265882

    Yes, we (Phylum) work closely with Github and reported this account to them.

  25. comment
    Comment #37264398

    We're actively working on this with our sandbox ( https://github.com/phylum-dev/birdcage ). We've wrapped the likes of pip, yarn, and npm already and are making moves to similarly …