Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

131–140 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#133
post #104

Earlier quoted context omitted.

[flagged]

Rules are put in place to be followed, for a reason. Capital letters at the start of the sentence increase readability. People who don't bother with them are being incosiderate towards their readers.

not at all

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#134
snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649

They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D

Their competence isn't as big as their fame, in my opinion.

Also one of their sales people insulted me over email, because apparently not being interested in buying their product means you're an incompetent developer who can only write software filled with vulnerabilities.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#135

Also interestingly the Snyk cofounder has started a competitor to cursor https://www.tessl.io/ https://techcrunch.com/2024/11/14/tessl-raises-125m-at-at-50... I hope there is no foul play.

Given how all my interactions with them have been extremely negative (see my other comment), I think it's rather likely that there is foul play.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#136

Earlier quoted context omitted.

[flagged]

It’s a low effort flex. As in: you’re unimportant, this is unimportant, and I’m very busy, so I can’t or won’t bother to capitalize. Which is ironic because it’s more effort to not capitalize.

it's many more keypresses, and using modifier keys is generally rsi-prone

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#137

I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

Why would you do anything but work related activities on a work machine. If you really want trust for software. Don’t use a computer.

It is good to wind down every now and then during work time.

Also, many people here work on multiple projects for different customers. Having a security breach for one affecting the other is not something you'd be happy with.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#138
post #134

snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…

"insulted me over email" - whoa, that's wild, do you still have the email? would be fun to see it :D

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#139

I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.

I just stick to using whatever is on my distribution for personal use.

For work use I use a work machine and if it gets compromised it's not really my own problem.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#140
post #134

snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…

> hey also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D

Well theres a sign of a good team.. /s

That's actually an interesting take, I haven't heard too much about them except that they do have an ego.

Post reply on HN