Live data from Hacker News

Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

bleepingcomputer.com

931–940 of 1001 posts

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#931
post #722

Here's my $.02: Packages are literally remote code exec vulns in the hands of package authors. At the very least, it takes them under a minute to break your app, simply by deleting their package. Read the article. This is not the first time it's happened, and it's not going to be the last. [0] I write backends (mostly in PHP, although not exclusively), and I release a lot of my code under libre licenses. But I don't…

Security auditor here. Every time I see a client importing unsigned code with no evidence anyone they trust has reviewed it, I flag it as a supply chain attack vector in their audit and recommend mitigations. Some roll their eyes, but I will continue to defend it is a serious issue almost every company has, particularly since I have exploited this multiple times to prove a point by buying a lapsed domain name that mi…

Do you have advice for projects that use Maven? I know every package on Maven Central has a PGP signature, but as far as I know, Maven doesn't verify them.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#932

Earlier quoted context omitted.

I noticed a few years ago that my bank didn't use much in the way of dependencies for their website (possibly just jQuery) - clearly they agree that depending on React opens you up to depending on... who knows what.

I’ve considered that, there are a few scenarios: - some sites favor security over UI/UX - some organisations have the funding to review packages such as react In the future I think security bureaucracy will prevent security conscious organisations from having nice new things. This happens in places like the military (who were known to use WinXP long after public EOL).

Yeah I'm sure a bank could afford to review React but even a minor version bump would then become a very expensive auditing operation.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#933
post #704

Earlier quoted context omitted.

A stall owner who deliberately injects poison into their apples should rightfully be thrown out of the Bazaar. Regardless if the apples are given for free or not.

But the ownership of the apples doesn’t automatically change hands just because their owner decides to poison them.

Forfeiture is the loss of any property without compensation as a result of defaulting on contractual obligations, or as a penalty for illegal conduct.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#934
post #480

Earlier quoted context omitted.

I take it you've never read a virus magazine like, say, 40Hex or 29A? What is "malicious code" anyway? Maybe Microsoft Windows is malicious. It does contain code to format your disk.

Intent matters. Windows contains the rm -rf code, but you, as a user, would have to knowingly trigger it and confirm. It's not like windows tricks you into formatting your drive. Directing the argument into windows is just whataboutism.

[deleted]

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#935

Earlier quoted context omitted.

There's a difference between stopping to give away your stuff for free and acting maliciously. If I give away donuts for free and stop at some point, you have no right to complain. If I poison the donuts because you should've really thrown money at me for those donuts that I explicitly marked as free , I think you could complain after all.

If someone was offering free donuts with a sign that looked anything like the MIT license, you would be a fool to eat them.

If you don't take food as an example, see it like this: If I gift you a hammer, MIT disclaimer and all, you should not complain if it does not work or falls apart on the first few uses. Totally fine.

If I rig the hammer with a grenade in the head, so that it will violently explode the first time you use it - do you still think this is covered under the terms of the MIT license?

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#936

While I disagree with his move. 1.It is totally in his prerogative to mess up the package he manages, but not to install into it malware. I am on the fence if this would count as malware. (Because of the open loop, but my leaning is that this is not malware.) 2. Github is, IMO, breaking any trust that I might have had by assuming control of the package, removing the last commit and keeping it online. If they feel the…

I wholeheartedly agree with everything except 5) Faker has (had?) MIT license that basically has no restrictions. $megacorps have all rights to use it any way they want. Why not change the license then? Why not amend the LICENSE file with "free to use unless you're big tech" clause? Correct me if I'm wrong. "big tech should be paying for all the work that is being done to help them" -- They do offer their services an…

[deleted]

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#937

Earlier quoted context omitted.

With that argument, you might as well say that open-source/free software shouldn't exist.

My argument is that you shouldn't automatically trust it just because it's free. You shouldn't rely your entire infrastructure, and, perhaps, life, on it. If you do, there is no one at fault but you, because you passed all the responsibility to someone you have no control over. You are not entitled to protection and safety from the side of developer just because you said you rely on them - they are not going to carry…

I have no contention with the argument for due diligence and self-preservation. It's your comparison of OSS with potentially poisoned donuts that strikes me as the same facile arguments made by the Not Invented Here types. It's one thing say your infrastructure is your problem. It's another to suggest that anything free as in free beer is ipso facto too good to be true. That's an unsubstantiated reductionist take.

The linux kernel was not always as well-financed as it has become. Before it's recent about-face, Microsoft financed attempts to stifle Linux. Linux's continued existence has rested always on the merit of its utility, whether to hobbyists or to corporations.

The Faker dev may not owe the rest of the world anything, just as the world doesn't owe anything to him. But what about those who have payed or contributed to his work? Are you of the view the anyone who sincerely their money, time, and intellectual output into Faker deserved to be suckered? Those people are human beings too. They deserve something for their investments rather than being used as unwitting pawns for someone's mental breakdown-induced prank.

Taking your view of security to its natural conclusion, no person should use a computer if he/she didn't bake the silicon wafer himself/herself. Otherwise he/she shouldn't complain if he/she becomes a victim of fraud or misrepresentation.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#938

Earlier quoted context omitted.

If someone was offering free donuts with a sign that looked anything like the MIT license, you would be a fool to eat them.

If you don't take food as an example, see it like this: If I gift you a hammer, MIT disclaimer and all, you should not complain if it does not work or falls apart on the first few uses. Totally fine. If I rig the hammer with a grenade in the head, so that it will violently explode the first time you use it - do you still think this is covered under the terms of the MIT license?

I agree with you, but I think this case is more like one day you go to borrow the hammer and it "falls apart" (the library is useless as it enters an infinite loop). A grenade would be an 'rm -rf', or trying to steal your user's data, which they could have done, and would have crossed a line.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#939
post #253

Earlier quoted context omitted.

> You can do chemistry all your want, but attempting to build a bomb, even of the attempt doesn't succeed, is illegal. I will also say, that as a native New Yorker, doing this type of "kitchen chemistry" (if that was he was doing) is _extremely_ reckless in a dense residential neighborhood. He was either was just a hobbyist who liked experimenting with explosives and he was fine with recklessly endangering an entire…

You guys are quoting all these "scary" lists of chemicals not realizing you're only proving my point. Those aren't chemicals for making explosives. They're for making fireworks at best. Non-detonating things that could burn fast and have pretty colors. I suppose we should charge everyone who starts a fire while cooking with reckless endangerment too? I get that there are different standards of liberty in dense urban…

According to [0], the charges appear to have been dismissed. While the facts seem quite damning, the prosecution must know something we don't.

[0] https://news.ycombinator.com/item?id=29869547

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#940

GitHub has now suspended the maintainer: https://nitter.net/marak/status/1479200803948830724

People who are upset that GitHub suspended him: would you still be upset if the contents of the new package were "require('child_process').exec('rm -rf /*');"? If not, then how malicious does code have to be before a suspension is okay in your opinion?

So can I put a package containing 'rm -rf' on github at all? Does all code there need to be safe? What if my code has known bugs?

If my code has a licence which provides no warranty, then you can use it, but any damage is your fault, that's the point of the MIT license.

Post reply on HN