Npm security post-mortem
blog.npmjs.org
Npm security post-mortem
1–10 of 65 posts
Re: Npm security post-mortem
#2Thanks for doing!
Re: Npm security post-mortem
#3Re: Npm security post-mortem
#4Re: Npm security post-mortem
#5Nice write-up and good on them for fixing that quickly, but it's a serious bummer they unnecessarily bring in the RubyGems incident as some sort of awkward "Well at least we didn't screw up that badly!" swipe. It's not relevant to anything else they said.
Re: Npm security post-mortem
#6Re: Npm security post-mortem
#7TL;DR always use a templating engine that makes you think about XSS and don't allow unsanitized user-provided HTML through raw.
Re: Npm security post-mortem
#8can anybody disclose some figures on how much ^lift (or competitors) costs, e.g.: for a 100K-line Python codebase? A rough ballpark would help a lot.
A good firm will help you do this, gratis, if you're serious about funding the work. We do it "on spec" for most of our clients, even though that work sometimes ending up helping a competitor deliver the project.
It's fine if firms ask you for lines-of-code counts, but if that's the only question they ask, I'd consider that a red flag.
Re: Npm security post-mortem
#9Nice write-up and good on them for fixing that quickly, but it's a serious bummer they unnecessarily bring in the RubyGems incident as some sort of awkward "Well at least we didn't screw up that badly!" swipe. It's not relevant to anything else they said.
I think what they're trying to say is that the bug is exactly as bad as the Rubygems incident, but they got lucky and it wasn't exploited.
Re: Npm security post-mortem
#10can anybody disclose some figures on how much ^lift (or competitors) costs, e.g.: for a 100K-line Python codebase? A rough ballpark would help a lot.
They were extremely easy to work with, and very fast about getting stuff to us and verifying when it was fixed, and I felt like we definitely got more than our money's worth.
A+, would recommend, will hire again.