snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…
"insulted me over email" - whoa, that's wild, do you still have the email? would be fun to see it :D
Snyk security researcher deploys malicious NPM packages targeting cursor.com
191–200 of 331 posts
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#192Earlier quoted context omitted.
Could you please explain a little more. I can use such practice in my dev workflow.
Sure. They don't include "node_modules" directory in their .gitignore file. So any third party code changes end up in git commits and are easily visible and reviweable. So running npm update/upgrade includes the code that changed in the dependencies in the commit.
In cases like that it helps to do npm install on the CI and make sure you end up with identical code. Decent trade-off.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#193Earlier quoted context omitted.
> "pretty irresponsible" Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.
It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#194I need to get serious about doing all development inside a virtual machine. One project per VM. There are just too many insidious ways in which I can ignorantly slip up such that I compromise my security. My only solace is that I am a nobody without secrets or a fortune to steal. IDEs, plugins, development utilities, language libraries, OS packages, etc. So much code that I take on blind faith.
Vagrant’s popularity seems to have died down with Docker containers but it’s by far my favorite way to make dev environments. Several years ago I worked somewhere that prohibited web browsers and development tools on laptops. If you needed to use a browser, you’d have to use one over Citrix. If you needed to code, you’d use a VDI or run the tools in a VM. At the time I thought their approach was clinically insane, bu…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#195Earlier quoted context omitted.
It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…
I wonder how viable it would be to find a public key your target owns and use it to encrypt the data you send back. Then you could prove to them that you exfiltrated real data without exposing it to anyone outside the company. Alternatively, you could hash it and say “Look, it’s a sha of your database password hyphen “yougotpwnd””
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#196Earlier quoted context omitted.
> "pretty irresponsible" Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.
It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…
look we had access to your Aws tokens, we could take over your account but we didn't steal actual token, we just got proof that we could access it
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#197snyk is the same company that instead of rotating oublic keys just… changes them without notice. https://github.com/snyk/cli/pull/5649 They also mark projects as "abandoned" if they move to any other forge that isn't github. And they stay abandoned even if new releases appear on npm/pypi :D Their competence isn't as big as their fame, in my opinion. Also one of their sales people insulted me over email, because appar…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#198Earlier quoted context omitted.
And what does that have to do with Snyk, other than that some of their employees use to work for IDF? I'm a US Navy veteran. Would you also stay away from my employers because they have veterans on staff? Seriously, I get what you're trying to say, but I don't understand the broader point you're trying to make. So Snyk has some ex-IDF employees. Find a high-profile infosec firm that doesn't. They military service the…
Without wanting to take a position here, the GP comment had a specific narrow point. The claim was that Snyk was founded by Unit 8200 members. Not that it had a few Israeli veterens, almost all Israeli's serve in the IDF after all. https://en.wikipedia.org/wiki/Unit_8200 To be fair I have a former Unit 8200 member in my larger extended family who left and has since been vocal in opposition to Netanyahu so membership…
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#199"no one can hack us" and then "you can't hack us, how dare you" game, 25 years and more
> "no one can hack us" Did Cursor made claims to this effect and invited public to hack them? Or are you equating someone saying they "take security seriously" to "it's an open season, please attack our systems."?
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#200Earlier quoted context omitted.
Talent or skills is essential but alone is not enough. while the size and quality of the talent pool helps it is not sufficient to explain the success rate, considering that there are similar or better quality talent pools which are larger in many countries around the world, but they don't have the success rates Israeli startups and 8200 ones specifically have compared to their home market and talent pool size. It is…
> benefits from this effect "Benefits" from whose perspective? For instance, the Brazilians (the State apparatus, specifically) are also benefiting [0], but are their citizens [1]? [0] https://www.jstor.org/stable/48595312 [1] https://idanlandau-com.translate.goog/2016/02/04/technologie...
Who in turn benefits from that in terms wealth, power, influence is whole different topic for which i have no expertise, i was only talking about frequency of successes in startup clusters.