Live data from Hacker News

Malicious crossenv package on npm

twitter.com

231–237 of 237 posts

Re: Malicious crossenv package on npm

#231
post #93
post #82

Earlier quoted context omitted.

Why would the malicious user advertise the email associated with crossenv as kent@doddsfamily.com and not kent@dodds.family? Attacker could control the latter and hand you an evil cert?

One would think you would do more than send an email if you're trying to verify. Websites, Twitter, Github, Keybase, etc.. It would be pretty hard for a bad actor to overtake the real author's entire Google-findable presence (assuming it's a reasonably popular package - why would you typosquat anything obscure). If all you do is send an email, then you haven't really done "due diligence" in any acceptable form.

Should I book a plane ticket to go verify 2 pieces of photo ID in person?

This idea that everyone will just verify with the author is insane.

Re: Malicious crossenv package on npm

#232

Earlier quoted context omitted.

I can't reply directly, but in another subtree you asked: > Which part of the statement implied "vilgilate justice." To put my own 2 cents in: Doxxing someone is generally considered an attack, at least in some internet circles. It's pretty vigilante if you ask me, especially when we've seen some pretty striking examples of doxxing gone wrong in the past.

If you connect to my resources and use my systems to hurt other people, you don't really have an ethical leg to stand on if I share what details about you I have with law enforcement and other service providers. It's absolutely an attack, but it's an "attack" of a kind that is acting to end misuse and widespread tampering. It's difficult to imagine a coherent ethical system that gives the author of malicious software…

Calling the police isn't doxxing someone, it's a reasonable response to a situation.

Vilifying them online isn't reasonable. It's how you end up with harassment, death threats, swatting, people going after your job, your family, etc...

It's a really shitty thing to do.

Re: Malicious crossenv package on npm

#233

Earlier quoted context omitted.

Like sibling says, doxxing implies that you'll post their personal info online. The problem does not lie in attacking bad people, the problem is that there is a high risk that you THINK you've identified who the bad actor is but actually the person you decide to "retaliate" against had nothing to do with what was done to you. That's why we leave law enforcement to the law enforcement officials and justice to the just…

> Like sibling says, doxxing implies that you'll post their personal info online. It's unfortunate that so many people don't know what the word means, because now we're redefining the word to a very specific and malicious definition that makes communication about nuances around the intersection of rights here more difficult. > there is a high risk that you THINK you've identified who the bad actor is but actually the…

> It's unfortunate that so many people don't know what the word means

When you're the one person in a conversation who has a totally different definition, you just might be wrong.

You're wrong. Give it up.

Re: Malicious crossenv package on npm

#234

Earlier quoted context omitted.

> I think folks just see the word "doxxing" and their pattern matching misfires. Or maybe you're trying to weasel out of what you said and are now going for broke. Linking once again to define words, we go to Wikipedia[0]: > Doxing is the Internet-based practice of researching and broadcasting private or identifiable information > Doxing may be carried out for various reasons, including to aid law enforcement, busine…

"Weasel?" I can see this is going to be a constructive dialogue. If I had wanted to "weasel" I would have deleted the post last night when it passed under the negative point threshold. I have absolutely 0 moral and ethical problems with publishing any details I have on a person who is using my system to attack other users. I think in fact this is a responsible thing to do, and necessary. In this specific case, I migh…

> "Weasel?" I can see this is going to be a constructive dialogue. If I had wanted to "weasel" I would have deleted the post last night when it passed under the negative point threshold.

I wasn't going to accuse you of being a weasel, but this is the most weasel-y thing I've ever seen.

Re: Malicious crossenv package on npm

#235
post #222
post #160

Earlier quoted context omitted.

It wouldn't. Nothing will help with package managers that follow the "wild west" or "any old crap" model where there is no maintainer or distributor between the developer and consumer that is allowed to perform any sort of quality control or sanitisation. This is what makes me hugely favour the "maintained" model followed by distributions or nix/guix. The wild west model scares the bejesus out of me to be honest.

The "wild west" model doesn't disallow anyone from providing quality control, it just doesn't enforce one particular person or entity's idea of what quality control should be.

I think we disagree with definitions of "quality control". My definition goes hand in hand with consistency.

Re: Malicious crossenv package on npm

#236

Earlier quoted context omitted.

You seem to have a handle on every aspect of this situation except what the actual attack we're discussing was. It was typo squatting.

And you like to assume things. Name canonicalization gets you part of the way there. But unless you want to go full-on namespacing then you must realize you are fighting a pointless battle. You cannot reasonably expect to save users from themselves in every way.

Npm has namespacing.

Re: Malicious crossenv package on npm

#237
post #233

Earlier quoted context omitted.

> Like sibling says, doxxing implies that you'll post their personal info online. It's unfortunate that so many people don't know what the word means, because now we're redefining the word to a very specific and malicious definition that makes communication about nuances around the intersection of rights here more difficult. > there is a high risk that you THINK you've identified who the bad actor is but actually the…

> It's unfortunate that so many people don't know what the word means When you're the one person in a conversation who has a totally different definition, you just might be wrong. You're wrong. Give it up.

I'm confused what exactly you want me to do?

I've said I have 0 problems publishing their data publicly. I'm happy to own even the stronger model of doxxing you lay out. I've put a few time qualifiers on it you didn't like.

But I have no problem burning the the identity people who think they can use me or my infrastructure to defraud others. Quite the opposite.

Post reply on HN