Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

1–10 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#3

Quoted post unavailable.

I rarely visit HN and mostly lurk here, not sure what you're trying to point out.

I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish

This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

Re: NPM package compromised by author: erases files on RU / BY computers on install

#4
post #3

Quoted post unavailable.

I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

I wasn’t suggesting any nefarious intent, only that this was the topic that made you go “Today is the day I post.”

Sorry to hear you were impacted by this. Software supply chain challenges are copious, unwieldy, and everywhere.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#5
I don't know how I feel about this.

One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole.

FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container running with root permissions.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#7
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#9
post #3

Earlier quoted context omitted.

I rarely visit HN and mostly lurk here, not sure what you're trying to point out. I was myself hit by the issue, unfortunately, and I strongly believe that weaponising open-source is not how things should be done, so I decided to post. An attempt to bring this into limelight, if you wish This incident sets a dangerous precedent in breaking a chain of trust that today's software development heavily relies on

I wasn’t suggesting any nefarious intent, only that this was the topic that made you go “Today is the day I post.” Sorry to hear you were impacted by this. Software supply chain challenges are copious, unwieldy, and everywhere.

>I wasn’t suggesting any nefarious intent,

Oh, please. The only thing missing was to accuse asn007 of being a "Russian troll", although I suppose you realized that that would not be appropriate in this case.

Just own up to your apology.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#10
post #7
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.

But this is pretty much the exact logic sanctions work by. Putin and his cronies might lose some super yachts but the main aim is to crash the Russian economy, which will hurt everyday Russians far more than any leader. Not that I have any better ideas, but you could argue this move is in a similar vein.
Post reply on HN