Live data from Hacker News

American NGO affected by your recklessness (node-ipc vulnerability)

github.com

1–10 of 22 posts

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#3
The maintainer, riaevangelist, appears to be breaking federal hacking laws by including the "peacenotwar" malware. They falsely claim it only shows a message on the users desktop, however if actually recursively overwrites the users files.

https://github.com/RIAEvangelist/node-ipc/issues/319

The maintainer has taken to banning anyone pointing this out. I don't believe this is someone with good intentions. Riaevangelist may have had their account stolen. Either way they are clearly operating in support of Russia under a false flag, an increasingly common and complex issue.

Given the supposed criminal nature of these acts GitHub and other serves must step in to remove the offending commits, releases, and maintainers. Allow someone else to fork it.

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#4

The maintainer, riaevangelist, appears to be breaking federal hacking laws by including the "peacenotwar" malware. They falsely claim it only shows a message on the users desktop, however if actually recursively overwrites the users files. https://github.com/RIAEvangelist/node-ipc/issues/319 The maintainer has taken to banning anyone pointing this out. I don't believe this is someone with good intentions. Riaevangeli…

Thank you for this breakdown. It wasn't clear to me at first what was going on from OP's link.

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#5
This issue sucks. Software packages should not intentionally cause data loss.

However, the person who filed this should have had better backups.

Edit: ok, re-read it. They have a process for backups but the invasion interrupted the process. That sucks.

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#6

The maintainer, riaevangelist, appears to be breaking federal hacking laws by including the "peacenotwar" malware. They falsely claim it only shows a message on the users desktop, however if actually recursively overwrites the users files. https://github.com/RIAEvangelist/node-ipc/issues/319 The maintainer has taken to banning anyone pointing this out. I don't believe this is someone with good intentions. Riaevangeli…

Thank you for this breakdown. It wasn't clear to me at first what was going on from OP's link.

Sorry about the bad title. First time submitting to HN, will be more verbose next time

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#7

Earlier quoted context omitted.

Thank you for this breakdown. It wasn't clear to me at first what was going on from OP's link.

Sorry about the bad title. First time submitting to HN, will be more verbose next time

Your title is fine! I just didn't know the context of what was going on with the project and its dependencies.

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#9

The maintainer, riaevangelist, appears to be breaking federal hacking laws by including the "peacenotwar" malware. They falsely claim it only shows a message on the users desktop, however if actually recursively overwrites the users files. https://github.com/RIAEvangelist/node-ipc/issues/319 The maintainer has taken to banning anyone pointing this out. I don't believe this is someone with good intentions. Riaevangeli…

> Either way they are clearly operating in support of Russia under a false flag

I don't see how this is clear at all. What is the evidence that this is a false flag?

There were plenty of comments on HN that were supportive of locking Russian citizens out of their accounts and disabling their domain names. I don't find it hard to believe that someone went a step further.

Re: American NGO affected by your recklessness (node-ipc vulnerability)

#10
Sounds like a fake story. What idiots would only store their war crime evidence database inside the aggressor state and not keep backups of it abroad?

If true, this arrangement was pretty much doomed to fail anyway. node-ipc did a good thing by notifying them of their folly before the Belarus KGB or Russian FSB did.

Post reply on HN