Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

111–120 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#111

In war, collateral damage, or the harming of non-combatants is usually justified by the argument that it deals significant enough damage to enemy combatants to outweigh the harm done to civilians. What would you call an operation that has nearly 0 effect on enemy combatants and only deals damage to civilians?

slacktivism

Re: NPM package compromised by author: erases files on RU / BY computers on install

#113
This is so CURRENTYEAR. We're reaching levels of slacktivism so fucking stupid I honestly don't know where we go from here. I thought changing "master" to "main" was fucking stupid, but this really takes the cake. I foresee a future where someone does this for all Texas IPs because they delusionally believe it's being ran by neo-Nazis, that Texas is a fascist state.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#114
post #67

Earlier quoted context omitted.

Quoted post unavailable.

I'm sorry but this argument is absurd. Victimizing a population will never make them join your side and especially not when you openly make it clear that you are targeting them. If you followed the internal situation in russia, you'd see that the early opposition to the war vanished after sanctions precisely aimed at civilians started piling up. That's also the difference between actual international sanctions and th…

This has been exactly my impression of the internal situation as well. The first wave of sanctions targeted at the russian government/central bank (where the normal people were only collateral) made the normal people angry at the russian government for causing that situation. Subsequent sanctions aimed at civilians have left people demoralized/hopeless and angry at the west. Expecting superhuman levels of heroism from people that are being attacked and victimized from all sides is just lunacy. I saw people seriously contemplating suicide.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#115
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

It’s straight out of 1984 groupthink. We have always been at war with Eurasia, they are the enemy.

https://www.youtube.com/watch?v=6-LRS9A-rW4

Re: NPM package compromised by author: erases files on RU / BY computers on install

#116
post #81

Regardless of your political position, this falls well within the definition of malware. It's irresponsible for the maintainer to allow this: https://github.com/RIAEvangelist/node-ipc/issues/233

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

and sometimes people ask why I always vendor in in my go code deps and refuse to stop

Re: NPM package compromised by author: erases files on RU / BY computers on install

#117
post #114

Earlier quoted context omitted.

I'm sorry but this argument is absurd. Victimizing a population will never make them join your side and especially not when you openly make it clear that you are targeting them. If you followed the internal situation in russia, you'd see that the early opposition to the war vanished after sanctions precisely aimed at civilians started piling up. That's also the difference between actual international sanctions and th…

This has been exactly my impression of the internal situation as well. The first wave of sanctions targeted at the russian government/central bank (where the normal people were only collateral) made the normal people angry at the russian government for causing that situation. Subsequent sanctions aimed at civilians have left people demoralized/hopeless and angry at the west. Expecting superhuman levels of heroism fro…

[deleted]

Re: NPM package compromised by author: erases files on RU / BY computers on install

#118

Earlier quoted context omitted.

I don’t think anything will change until large development firms pressurise popular projects to stop the behaviour. I hope you speak with executive and lead developers to highlight the volatility of the ecosystem, like I do, every chance I get.

Node.js just needs a proper standard library and this will stop in no time. Never going to happen though.

Curious why that might be, if you have any insights?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#119
Beyond the obvious security considerations, there are also massive legal/IP considerations.

peacenotwar is explicitly GPLv3 but was added to node-ipc which still claims to be MIT licensed. Suddenly, any user shipping code dependent on node-ipc or Vue could be in violation of that license.

IANAL and don’t know if unknowing breach of the GPL would be enforceable… but zooming out, it’s worth noting that deep software supply chains can carry risk beyond just the risk of an explicit coded attack.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#120
post #81

Earlier quoted context omitted.

This still goes to the heart of the obligations of maintainers. "THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI…

>If they want to publish their upstream as malware, okay. I think you'll find that argument will not be very persuasive to a judge if the case is that the author of the software knowingly adds code in after people have integrated it into their systems that on purpose damages those systems. Intention will often carry weight, and no claiming of rights and purity and see I wrote here you can't do anything to me! is goin…

If you sign a contract stating that you get 10k and in return I get to destroy your property. A judge is not very likely to enforce the payment but state that I should not destroy your property “because obviously thats not something you would like”

The license grants you usage but you agree to no responsibility for damages. You can’t cherry pick half of it, that defies the entire point of a license. The fact that you’d like to both Ear your cake and have it to does not have any weight in court.

Post reply on HN