Earlier quoted context omitted.
This is a joke right? Can’t say I’ve ever heard of USB ports referred to as “holes”.
> Can’t say I’ve ever heard of USB ports referred to as “holes”. I cannot be bother to remember every hole name. They're all USB anyway, the difference is that some are A, C, or Lightning, I bought a new MacBook and it has that magnet hole, what is that called? I'm not following.
DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
201–210 of 296 posts
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#202But never ever anyone was rooted because of malware that was snuck into an official .deb package.
That was the concept of "stable" in the good old time, when software was really an "engineering" field.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#203Earlier quoted context omitted.
> Can’t say I’ve ever heard of USB ports referred to as “holes”. I cannot be bother to remember every hole name. They're all USB anyway, the difference is that some are A, C, or Lightning, I bought a new MacBook and it has that magnet hole, what is that called? I'm not following.
Are you not around hardware that much? This is stuff people who work in tech deal with every day, it's too hard to keep track of the names of the three different ports that you use ubiquitously? When someone asks you what charging port you need, do you just say "big square one" or "the iphone one"? Do you then have to clarify "the old iphone one, not the new one"?
The stuff I deal with every day is centering divs
> it's too hard to keep track of the names of the three different ports
it's more than three ports.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#204I've been critical of blockchain in the past because of the lack of use cases, but I've gotta say crypto functions pretty well as an underlying bug bounty system. This probably could have been a much more insidious and well hidden attack if there wasn't a quick payoff route to take.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#205Earlier quoted context omitted.
Are you not around hardware that much? This is stuff people who work in tech deal with every day, it's too hard to keep track of the names of the three different ports that you use ubiquitously? When someone asks you what charging port you need, do you just say "big square one" or "the iphone one"? Do you then have to clarify "the old iphone one, not the new one"?
> This is stuff people who work in tech deal with every day The stuff I deal with every day is centering divs > it's too hard to keep track of the names of the three different ports it's more than three ports.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#206Earlier quoted context omitted.
Genuine question: why is `curl https://trusted-site.com | sh` a security risk? Fundamentally, doesn't the security depend entirely on whether https is working properly? Even the standard package repos are relying on https right? Like, I don't see how it's different than going to their website, copying their recommended command to install via a standard repo, then pasting that command into your shell. Either way, you…
Current incident confirms that we can't trust to authors of DuckDB, because they can't evade a trivial phishing attack. Tomorrow they will do it again, and attackers will replace binary files that users download with this random script. Or this script will steal crypto/etc. To make attack vector difficult for hackers, it's preferable to download any software as packages. On linux it looks like `apt install python3`.…
for MacOS they have it in brew, which is also you can use on linux, also it is available in nix.
I think the problem is that there are so many linux distros with their own package repositories, that it is very untrivial task to include package into most of them if maintainers are not proactively interested.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#207Earlier quoted context omitted.
Or Cargo. I compiled Zed with release mode, pulled in 2000 dependencies. It does not fill me with confidence.
On a related note, the maintainer of the compromised npm packages, debug and chalk, who got pawned, is creating an operational system in rust. https://github.com/oro-os https://news.ycombinator.com/user?id=junon
I wonder if it really is only npm that got compromised.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#208Just for context. DuckDB team is consistently ignores any security practices. The single one method how to install DuckDB on laptop is to run `curl https://install.duckdb.org | sh` I've requested to deliver CLI as standard package, they have ignored it. Here is the thread https://github.com/duckdb/duckdb/issues/17091 As you can see that it isn't single slip due to "human factor", but DuckDB management consistently pu…
Genuine question: why is `curl https://trusted-site.com | sh` a security risk? Fundamentally, doesn't the security depend entirely on whether https is working properly? Even the standard package repos are relying on https right? Like, I don't see how it's different than going to their website, copying their recommended command to install via a standard repo, then pasting that command into your shell. Either way, you…
Running scripts even more so.
One day someone might decide simply to exploit whatever trust they have.
Actually I wonder how much black market would pay for rights to change reasonable popular script like that...
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#209This is critical infrastructure, and it gets compromised way too often. There are so many horror stories of NPM (and similar) packages getting filled with malware. You can't rely on people not falling for phishing 100% of the time. People who publish software packages tend to be at least somewhat technical people. Can package publishing platforms PLEASE start SIGNING emails. Publish GPG keys (or whatever, I don't car…
Maybe don't allow changing the email address right after changing 2fa?
And if the email is changed, send an email to the original email alllowing you to dispute the change.
Re: DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware
#210Earlier quoted context omitted.
> This is stuff people who work in tech deal with every day The stuff I deal with every day is centering divs > it's too hard to keep track of the names of the three different ports it's more than three ports.
Also USB A is not even square, it's a rectangle