Live data from Hacker News

NPM package compromised by author: erases files on RU / BY computers on install

snyk.io

171–180 of 188 posts

Re: NPM package compromised by author: erases files on RU / BY computers on install

#171
post #126

Earlier quoted context omitted.

The average russian citizen supports the war

Maybe, but you can't prove that with polls. It's illegal to oppose the war in Russia. The polls everyone is citing were conducted by state TV. Presuming they didn't just make up their data, imagine you got a call from state TV asking "if you support the special military operation to denazify Ukraine". Your friend just told you they know someone who knows someone who was arrested and charged with oppositing the war fo…

If you look at the details it's also more optimistic than you might think. For example 25% of under-30s support the war.

https://meduza.io/en/feature/2022/03/07/russia-s-tricky-opin...

Re: NPM package compromised by author: erases files on RU / BY computers on install

#172
post #126
post #108

Earlier quoted context omitted.

This is the sad thing about all of this. Many people are demonizing average Russian citizens for the actions of their government. When the US invaded Iraq in 2003, I was very much against it, but felt powerless to change the course of my government. (And the US government kept on doing what it felt like, no matter how unjust its actions.) While I was ashamed of my country's actions, I didn't think it would be fair fo…

The average russian citizen supports the war

No post body was provided.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#174

Earlier quoted context omitted.

I have seen enough war crime photage that I am willing to accept any amount of civilian damage against Russia that is going to have an effect on the war, short of nukes. When your government uses hospital locations as a target list and drop bombs on shelters, I don’t care if your files gets deleted.

> I have seen enough war crime photage You have participated in too many instances of two minutes hate and were gaslighted by propaganda. I laugh hysterically (in a very sad way), as I scroll through /r/Ukraine and see yet another video headlined as "Another Russian war-crime in Ukraine", that I had already seen few years ago headlined as "Ukrainian war-crime in Donetsk". There is no truth anymore, literally every ma…

To me this is a call to get off the corporate controlled internet. People have been warning about this since like 2010, and I always agreed that there could be a danger, but I never realized just how bad it already is.

This is a kind of phenomena that I can only describe as internet psychosis. Considering how toxic all these platforms are, it's quite plain to see now that the people captured by them are not invested in reality and seem to be coalescing into a kind of psychotic frame of mind. Even people who aren't captured are affected by it, and I have no doubt that I've been subjected to multiple psyop and propaganda campaigns just by perusing sites like Twitter, Reddit and Youtube.

The modern internet is a warzone that weaponizes emotions. IMO, for the good of society and the future of the internet people need to get out as soon as possible and build new services that don't play into this.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#175

Earlier quoted context omitted.

That is not the position ctvo is making at all. He never said he was in support of malware. He is stating that there should be no legal ramifications. The person who added the malware is definitely a piece of shit but i also agree he should not face legal ramifications. This is his code and he is allowed to do with it whatever he wants. It is the consumer to safe guard against external code. Legal ramifications would…

I too would normally agree if the software wasn't actually malicious this time. It is one thing to create an infinite loop in a package that can simply be terminated, but a whole other can of worms to actually start removing users files. I generally agree with what you are saying that open source developers don't owe anyone anything, but there is a line, otherwise think about the precedent it sets when open source di…

The original statement was that this person isn't likely to face legal recourse. The comment I was replying to was very lengthy, but never addressed that statement or made a LEGAL argument that this person would face legal recourse, hence my reply.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#176
post #19
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

> I don't know how I feel about this. > One hand, this is a seemingly non-violent and subtle way to protest. You can't be serious. Being non-violent and subtle is no excuse for deliberately making software have real side effects on a computer that it's not advertised to do, especially a node library. Node modules for some reason tend to be very small and have trivial tasks like checking if something is a number. Imag…

I didn't condone anything or anyone, I just stated I wasn't sure how to feel about it.

Anny assumptions or claims beyond that are your own delusions.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#177
post #32
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

Its childish. Striking out maliciously at random web developers surrounded by state propaganda is counter-productive. This just annoys them and feeds the narrative that they're under attack by the West who hates them. I would imagine web developers over there, being more educated, technical, and exposed to the West, would be the ones less likely to support the war. There's nothing subtle about wiping files, why not p…

Your suggestions are also childish and just as flippant.

I don't know how to feel about this because it's not much different than sanctions in theory (very different in execution). Cause pain for people so they "force internal change."

It's not something to root for gleefully.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#178
post #7
post #5

I don't know how I feel about this. One hand, this is a seemingly non-violent and subtle way to protest. On the other, the potential collateral damage is huge and just burns all trust with this developer, and is a net harm to the ecosystem as a whole. FOSS is great, because we were actually able to track the changes here. But it also points out how many packages go un-checked and just installed into a container runni…

it isn't going to stop Putin but it could negatively impact normal people. in no universe will the handful of Russian programmers impacted by this rise up and overthrow their government. but they will be forced to work extra hours cleaning up any damage this caused to their system. This is really lame virtue signalling that only harms fellow workers because their government is terrible.

So sanctions? I get it, collateral damage is indeed collateral. That's why I don't know how to feel.

If this move broke some key software used on the battlefield, would we all be so quick with our positions?

Re: NPM package compromised by author: erases files on RU / BY computers on install

#179
post #52

This is crazy. Are you hating on every Russian now ? Nobody is chocked by how anger against the the russian state shifted to hate against russian people ?

Why is anyone surprised that this is happening. All you had to do is look at how people treat Asian people to realize what was going to happen to Russian people.

Re: NPM package compromised by author: erases files on RU / BY computers on install

#180

Earlier quoted context omitted.

>If they want to publish their upstream as malware, okay. I think you'll find that argument will not be very persuasive to a judge if the case is that the author of the software knowingly adds code in after people have integrated it into their systems that on purpose damages those systems. Intention will often carry weight, and no claiming of rights and purity and see I wrote here you can't do anything to me! is goin…

If you sign a contract stating that you get 10k and in return I get to destroy your property. A judge is not very likely to enforce the payment but state that I should not destroy your property “because obviously thats not something you would like” The license grants you usage but you agree to no responsibility for damages. You can’t cherry pick half of it, that defies the entire point of a license. The fact that you…

People are so clueless about law, this comment is a great example. A licence is worth jack shit in a criminal case (which this would be, if prosecuted).
Post reply on HN