Live data from Hacker News

Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

bleepingcomputer.com

651–660 of 1001 posts

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#651
post #175

Earlier quoted context omitted.

I couldn't help but think the same thing. Seems like an incredibly immature way to handle it. He could have easily set an end date and state nothing will be maintained beyond that date. It's not a good look.

marak has a documented history of mental illness and downright odd behavior. Talented dev and troubled individual. There's a pretty concise video covering what went down with some history here: https://www.youtube.com/watch?v=R6S-b_k-ZKY

No post body was provided.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#652
post #561

Earlier quoted context omitted.

no its a criminal act. crashing RANDOM servers that you DONT know what they do is not a protest.

Your argument could be used to describe any software defect, whether malicious or accidental. Open-source code is mostly not produced with any knowledge of downstream servers; that's the responsibility of the server owners. The software developers also have a responsibility to ensure they trust the author and are okay with the code they are importing into their own projects.

No it only describes malicious intent which IS required for it to be malware aka criminal.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#653

Here's my $.02: Packages are literally remote code exec vulns in the hands of package authors. At the very least, it takes them under a minute to break your app, simply by deleting their package. Read the article. This is not the first time it's happened, and it's not going to be the last. [0] I write backends (mostly in PHP, although not exclusively), and I release a lot of my code under libre licenses. But I don't…

I wish there was a package manager for node.js that is made for "static" or offline usage, and is able to compare headers of libraries before upgrading them.

But here we are, 10 years in, with nobody giving a damn about semantic versioning.

Life could be so much easier with an actual package manager that isn't just some git clone replacement.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#654
post #453

It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…

Use a language where you don't need to pull in 100 dependencies to create a useful application/service.

Cool use a lang without a developer ecosystem got it.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#655

Earlier quoted context omitted.

> I think Marak is teaching an important and principled lesson here. What lesson is that?

Quoted post unavailable.

> these trillion dollar corporations just take and take and never give,

Which trillion dollar corporations are these?

A quick google says "Apple, Microsoft, Alphabet, Amazon, Telsa, Meta, NVidia, and Berkshire Hathaway" are the the only trillion dollar companies

Except for the last one all of those companies give back vast amounts of open source support. All you using VSCode for free, that's Microsoft's payback. Oh, and Microsoft pays for NPM hosting and github, also Typescript, C#, F#, .NET. Hardly not giving anything back. Apple gives Swift, Clang, LLVM, Webkit to name a few. Alphabet, Go, Chrome (which also means Electron on which VSCode is running), Android, and plenty of others. Meta provides React, Redux. Not sure what open source Tesla gives back but they have given their patents (https://www.tesla.com/blog/all-our-patent-are-belong-you). Nvidia gives away tons of open source as well (https://developer.nvidia.com/open-source)

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#656
post #608

Earlier quoted context omitted.

You're new so I won't hold it against you. Aaron Swartz would have 100% approved of this.

I'm not new, and no he wouldn't have.

Aaron was known for circumventing systems.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#657

Earlier quoted context omitted.

> It's his code to break if he wants > I don't understand why If he can break his code because he is the owner then shouldn't the same reasoning apply for Github suspending the account?. It is their website and their rules. Keep in mind Github owns npm and the author has published a malicious package to npm which has 20 millions of downloads so I'm not surprised.

For some reason, people are adopting the ideologically inconsistent position full property rights to the dev, but no property rights to Github.

IMO they are kind of different things. The dispute about the code itself seems to be more of a licensing thing whereas the GitHub itself seems to be a property thing.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#658

It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…

But "vetting" is still relying on the free labor of other and really doesn't change the business model and rectify the underlying problem with open source.

You really need an organization which sponsors and directly hires coders that are maintaining critical infrastructure.

(Of course the npm world is a bit insane where stuff as trivial as leftpad can be critical infrastructure. Don't really think someone needs a $200k/yr salary to maintain just that)

There's an interesting bit of social psychology here where the top reaction to this isn't "lets try to sort out how to pay all the people who are doing all the free work" (and I'm really thinking more the log4j and openssl people and the whole broader ecosystem problem this highlights) and instead it is "how do we keep being exploitative and just outsource the hard job of vetting everything?" I'm pretty sure Google will probably get some AI people onto the problem though, there's clearly a business model there.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#659
post #612
post #277

Earlier quoted context omitted.

Why is that scary? If you do bad things, you're going to get banned. This guy abused Github to distribute malicious code to thousands of projects. If losing your Github means losing your projects, that's on you for being lazy/irresponsible with them. Git is already decentralized, and anything important should be cloned on something you own.

What's actually malicious about the code? It's an infinite loop that logs to stdout. Sure, it's not what the library is supposed to do, but is it malicious code?

I think the intention is to cause downstream users to spinlock.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#660

It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…

I will happily provide this service to you. In fact, I already created a Linux distro specifically for rolling back all the brain damage and misfeatures in mainstream Linux that have crept in over the past 15 years. It contains just over 1,000 packages, with not a few patches/bug fixes by myself and others.

If you want to use this distro in your own company with full time support and continuous upgrades by yours truly, my yearly salary will be 220,000 USD, please--not counting any donations you decide to make to individual software authors to ensure your use case is covered by their software, as the above amount covers only my personal salary and considerable expenses.

A large discount is potentially available should other corporations avail themselves of this opportunity and also help cover my salary and expenses. Contact me at [email redacted].

I'm not holding my breath that anyone will take me up on this opportunity, so this distro will just have to remain for my exclusive use only, I'm afraid.

Post reply on HN