Live data from Hacker News

Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

bleepingcomputer.com

661–670 of 1001 posts

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#661

Earlier quoted context omitted.

Except the license does say so

The license does say what? The license doesn't say any payment is necessary. The license doesn't say new versions will still work. The license doesn't say anything about complaints. If it's valid to complain about code breaking, it should also be valid to complain about lack of payment. These complaints are outside of the legal mandates of the license.

The license says the code is "AS IS".

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#662
post #441

Earlier quoted context omitted.

Yeah I also don’t understand. But then again.. the js ecosystem is one big pile of turds.. Tech cycles with people who reinvent the wheel and keep making the same mistakes All these problems have long been solved

They were solved in a way that slowed progress. So invariably, people discovered that if they threw out the complexities of the solutions, they could make faster progress. Then they eventually ran into the corner cases. That's the time loop that keeps happening.

Yeah, this seems less like actual progress and more that people wanted to drive in circles faster.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#663
post #569

Earlier quoted context omitted.

Yeah but in this case you might not be directly dependent on colors. You might be dependent on http-server, which is in turn dependent on colors. You can only roll back http-server, and unless http-server rolls back colors, you are stuck.

So set it in overrides? Blacklist it in your private mirror? It’s your project, your environment, and your computer, you’re never stuck.

Oh I agree, nobody is stuck. I'm just pointing out that, sure, there are messy workarounds, but in this case it is not as simple as "rollback".

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#664
post #339

Try to look at it from another point of view. Marak is fed up of all these billion dollar companies (and other small projects) using his code, he has some financial problems and so he decides to teach them a lesson. I sympathize and for sure if I were responsible for a big company and I was using an open source component/project I would donate something. We all have to rethink of how the open source funding is suppos…

Like, I understand it. And he could easily have done something much more malicious, like running a ‘rm -rf /‘. This seems on the level of a very misplaced prank. I feel like people (and especially corporations thst have freely used the library for years) are overreacting a bit. This is just a warning signal that we depend on random packages too easily. The only thing standing between many products and disaster is the…

I think people overreact (or at least I overreact) because of two things:

1. A kind of "psychological contract" is in place between a package maintainer/creator and the developers using it and that is somewhere along the lines of "assuming good faith" or "good intentions" from the maintainer and giving back somekind of "kindness" to maintainer specially in cases of of some OSS (MIT, Apache, BSD-2/3 ...).

This maintainer broke this contract - the trust of its users. They are pissed and rightly so. He broke is because he also felt that another "psychological contract" was broken between himself and the market. So his users are pissed because they see this as retaliation from the maintainer to them without them doing anything to merit this.

2. Another aspect is that he could have gone multiple ways to try to get money from companies by pivoting his projects. But his action is an emotional response with a hint of political activism that caused damage also to developers who are not having the choice (they are not decision makers or not managing budgets) nor the desire to be part of this. So for them there is another breach of "contract" happening: using those libraries seems to have a hidden term "you will be used as collateral when needed in my fight against big companies" which they did not agreed and was not explicit.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#665
post #350

Earlier quoted context omitted.

People who are upset that GitHub suspended him: would you still be upset if the contents of the new package were "require('child_process').exec('rm -rf /*');"? If not, then how malicious does code have to be before a suspension is okay in your opinion?

I'm not entirely versed in NPM politics, but: 1) GitHub and npm are supposed to be separate things. There might be stuff in that GH account that affects other ecosystems. By all means block the npm account, but that should be it. 2) in the end, one is responsible for the packages one pulls. We keep relearning that lesson over and over, because global package repositories made us lazy.

> GitHub and npm are supposed to be separate things.

Is that going to be true forever? I would assume not. There is already much deeper integration between github and npm than there was a few years ago, and Github seems to be going fairly deeply into CI and distribution.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#666

Earlier quoted context omitted.

Quoted post unavailable.

> these trillion dollar corporations just take and take and never give, Which trillion dollar corporations are these? A quick google says "Apple, Microsoft, Alphabet, Amazon, Telsa, Meta, NVidia, and Berkshire Hathaway" are the the only trillion dollar companies Except for the last one all of those companies give back vast amounts of open source support. All you using VSCode for free, that's Microsoft's payback. Oh,…

No post body was provided.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#667
post #153

Earlier quoted context omitted.

How about using dependencies but pinning the version and only updating if you know what the update contains? I'm still continually baffled that we ended up in a world where automatically accepting updates from every dev and their dog is not just the norm but recommended practice.

> if you know what the update contains? I think anyone who thinks they're doing this is fooling themselves. You can review code for accidental vulnerabilities but if someone is trying to slip in a backdoor it shouldn't be hard to do so in a stealthy manner. The reality is that the entire dependency concept is just broken. There is an implicit trust that all dependencies are equally trusted. Your logging package is ju…

Adding permissions is a reasonable step, but I don't think it solves the problem. We know, it's very hard to get granularity right with permission systems and there is a strong temptation to just give everything all permissions.

Dependencies with dangerous but necessary permissions can still abuse them: Your network library will still be able to add a bitcoin miner.

What happened if an update requests a new permission?

Also, how would that have prevented the current situation? Infinite loops are famously hard to detect and prevent automatically.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#668
post #645
post #409

Earlier quoted context omitted.

"inspired" my ass. It's a fork, not keeping the licence terms. https://news.ycombinator.com/item?id=27254092

seems like he has a history of this (HN 2010): https://news.ycombinator.com/item?id=1448309

and he seems quite proud of getting banned from Github in 2013: https://youtu.be/varf6oWaFtU?t=202

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#669
post #253
post #224

Earlier quoted context omitted.

Sorry, this is bullshit. > When investigators entered Squires' apartment to look further, they found more bomb making items including potassium nitrate. Magnesium powder, sulfur powder, copper powder, aluminum powder, hobby fuse and mixing cups were also discovered in the home. "The chemicals separately are what they are, but taken together they can assemble an explosive device," Deputy Commissioner of Intelligence a…

> You can do chemistry all your want, but attempting to build a bomb, even of the attempt doesn't succeed, is illegal. I will also say, that as a native New Yorker, doing this type of "kitchen chemistry" (if that was he was doing) is _extremely_ reckless in a dense residential neighborhood. He was either was just a hobbyist who liked experimenting with explosives and he was fine with recklessly endangering an entire…

You guys are quoting all these "scary" lists of chemicals not realizing you're only proving my point. Those aren't chemicals for making explosives. They're for making fireworks at best. Non-detonating things that could burn fast and have pretty colors.

I suppose we should charge everyone who starts a fire while cooking with reckless endangerment too? I get that there are different standards of liberty in dense urban areas but I don't think this is beyond them. It's just cops and feds talking up their non-bust.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#670

Earlier quoted context omitted.

Moreover, anyone who either has malice intentions (or depend on other packages, of whom authors do) can make the whole process much less noticeable with relying on variables from URLs that get executed, which may themselves be linked to other dynamic dependencies, creating all sorts of logic/time bomb or RCE attacks. That kind of behavior would be practically impossible to code-review for lots of packages that rely o…

This is what the folks working on WASM/WASI and related projects are trying to achieve. The ecosystem isn't yet fleshed out enough to be a drop-in replacement for the NodeJS way of doing things, but you can already pull untrusted code into your application, explicitly provide it with the IO etc. capabilities it needs to get its job done (which is usually nothing for small packages, so not much bureaucracy required in…

sounds like java's SecurityManager all over again
Post reply on HN