Live data from Hacker News

NPM won't publish packages containing the word keygen

mamot.fr

161–170 of 269 posts

Re: NPM won't publish packages containing the word keygen

#161
post #112

Earlier quoted context omitted.

With respect, all of that for some bokeh? Is it worth it for y’all? Do you know how many folks just leave when the stuttering starts?

The entire lava lamp effect is a shader, not just the bokeh. :) I haven't noticed any drop in registrations, conversions, or any noticeable differences in traffic patterns after launching the redesign, so I'm not sure if this is actually happening. Though it's a valid concern and issue, and I do want to fix it. And I appreciate all the reports. I think it may be a retina resolution issue, but could be wrong. On launc…

> What I wasn't expecting was so many tier 3 devices that aren't really what I'd consider "tier 3." I was expecting all tier 3 devices to be gaming-level GPUs.

Could be the detection of GPUs doesn't work correctly? My nVidia 1080Ti is detected as nVidia 980Ti, and a sibling comment mentions an integrated laptop GPU being detected as tier 3 with isMobile=false.

Re: NPM won't publish packages containing the word keygen

#162
post #128

Earlier quoted context omitted.

With all due respect, this is possibly the dumbest rebuttal I've heard. Why do I need a powerful GPU or even need my GPU to waste compute cycles just to view a webpage? Just get rid of it entirely. The visual flair is not adding any value. It's a performance drag, highly distracting, and serves no useful purpose whatsoever. This "trend" in modern web design is truly infuriating.

Wasn't expecting so much candid feedback today. There was a Launch HN yesterday that had a 3D rubik's cube on their home page. It was literally pointless. But kind of neat. But you probably hated that as well, if I could assume. But I say that to point out that lots of companies do it, sometimes simply because we can (just look at Stripe and GitHub). I think the lava lamp effect is cool. The perf issues can and will…

Yes other companies have animations but they make sure it performs well across browsers and OSs.

Mac+Firefox users are probably in your customer base. Listen to the feedback.

Re: NPM won't publish packages containing the word keygen

#164
post #128

Earlier quoted context omitted.

With all due respect, this is possibly the dumbest rebuttal I've heard. Why do I need a powerful GPU or even need my GPU to waste compute cycles just to view a webpage? Just get rid of it entirely. The visual flair is not adding any value. It's a performance drag, highly distracting, and serves no useful purpose whatsoever. This "trend" in modern web design is truly infuriating.

Wasn't expecting so much candid feedback today. There was a Launch HN yesterday that had a 3D rubik's cube on their home page. It was literally pointless. But kind of neat. But you probably hated that as well, if I could assume. But I say that to point out that lots of companies do it, sometimes simply because we can (just look at Stripe and GitHub). I think the lava lamp effect is cool. The perf issues can and will…

Looks good on the 4090 here, ship it

Re: NPM won't publish packages containing the word keygen

#165

Every time npm comes up I remind everybody that npm is shit, and nobody should use it. They have a bad track record of doing things right and bad attitude when told. But you keep using it. I refuse to use it at work and refuse to use it in personal life. It’s not real software and will cause you harm.

Fun fact. Several years ago I started getting charges from NPM, which although I am a software developer I have never used. I cancelled my credit card multiple times, but they kept appearing each month. I went to my bank, Bank of America, and they claimed that there was nothing they could do because NPM was using some sort of option they had to follow me when I got new credit cards. I don't know what kind of option t…

Ok, I'll bite. There is no way a merchant can learn a new card number other than from the cardholder, or from a thief who got it from the card/cardholder. Not from any upstanding entity.

If you merely got a new expiration date, security code, etc. without also changing the card number, they could "follow" that by submitting a transaction without those extra pieces of information, at greater cost and risk to themselves, though.

I'll happily take downvotes if I'm wrong, for being assertive without a source.

Are you sure NPM was actually charging your card directly, and not a digital wallet or similar virtual card thing which you kept active?

Re: NPM won't publish packages containing the word keygen

#166
post #143
post #128

Earlier quoted context omitted.

Wasn't expecting so much candid feedback today. There was a Launch HN yesterday that had a 3D rubik's cube on their home page. It was literally pointless. But kind of neat. But you probably hated that as well, if I could assume. But I say that to point out that lots of companies do it, sometimes simply because we can (just look at Stripe and GitHub). I think the lava lamp effect is cool. The perf issues can and will…

I'm sorry, but what should just. be a _progressive enhancement_ in this case completely ruins the user experience for me. However, I'm probably not your target audience, I'm just commenting on this trend in general.

It literally is a progressive enhancement, so I'm not sure what your point is.

There's clearly bugs where it's enabled where it shouldn't be, and that's certainly an issue, but the comments here make it clear that it gets disabled automatically on lower-end devices.

Re: NPM won't publish packages containing the word keygen

#167
post #64

Earlier quoted context omitted.

Malicious unchecked code in postinstall can just be moved to runtime so blanket blocking postinstall is as effective a solution to supply chain attacks as the solution of blocking npm packages with the word "keygen" in them is to the problem of .... js based keygens??? There are many legitimate purposes for postinstall scripts yet the anti-postinstall crowd acts like they solved security issues with this one easy ste…

Postinstall scripts run without any interaction before the developer has any chance of reviewing the code. They are a very bad thing.

"any chance"???

I can't square this circle of someone being paranoid about postinstall script but at the same time thinks the first chance to review dependency code is after doing a `npm i`.

Check the git repo of the library you are installing beforehand if you're so paranoid about postinstall.

And above that, never install any library for which the source is not readily available. This is the most basic first line of defense.

username checks out.

Re: NPM won't publish packages containing the word keygen

#168

Earlier quoted context omitted.

The Scunthorpe problem all over again. https://en.wikipedia.org/wiki/Scunthorpe_problem

I only recently learned that my username for 20 years has "orgy" in it, and I've been getting blocked by many games

20+ years of this handle online without problems, and I found out trying to sign up for Stern Pinball Insider that "bint" is a dirty word: https://en.wiktionary.org/wiki/bint

Re: NPM won't publish packages containing the word keygen

#169
post #15

I thought buttbuttination taught everyone how incredibly stupid this is 25-30 years or so ago already? But no. Just a few years ago I tried to enter an answer into a Hungarian Q&A site recommending to take the Algeciras-Tangier ferry and the answer was refused. https://en.wiktionary.org/wiki/geci

The Scunthorpe problem all over again. https://en.wikipedia.org/wiki/Scunthorpe_problem

Filters like that are so trivial to bypass on a higher level too. Look at how many gamer or forum tags are “Lovecraft’s Cat”. And good luck catching those cases on a non-manual basis.

Re: NPM won't publish packages containing the word keygen

#170
post #19

I run a business called Keygen [^0], and own the @keygen namespace on npm. We’re working on a Node SDK, so this isn’t good to hear. I’ll open up a discussion with them and see what we can do. [^0]: https://keygen.sh

Could it be that they are doing this as a way of preventing packages spoofing the namespace (ex. 'keygen-core')?

That would be terrible, because if someone owns the @express namespace that isn't express team (not gonna happen, just illustrating why this idea is bad), then goodbye all `express-*` packages.
Post reply on HN