Live data from Hacker News

Snyk security researcher deploys malicious NPM packages targeting cursor.com

sourcecodered.com

211–220 of 331 posts

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#211
post #193

Earlier quoted context omitted.

It's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token rewar…

Cursor does not have a bug bounty though, and its hard to see how this constitutes anything other than a direct attack on them, their users, or both. "The incentive structure made me do it" does not justify acting like a criminal.

Cursor asks researchers to report vulnerabilities to their GitHub security page.

The same incentive to show impact applies even without a paid bounty.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#212
post #43

Earlier quoted context omitted.

Vagrant’s popularity seems to have died down with Docker containers but it’s by far my favorite way to make dev environments. Several years ago I worked somewhere that prohibited web browsers and development tools on laptops. If you needed to use a browser, you’d have to use one over Citrix. If you needed to code, you’d use a VDI or run the tools in a VM. At the time I thought their approach was clinically insane, bu…

I still like Vagrant. But I believe it's yet another victim of the Hashicorp license change debacle from a year or two ago. Unlike with Terraform/OpenBao, I know of no community effort effort to keep the open-source version of this project alive. The latest open source version is still available on the Ubuntu repo, but who knows who long it will work until somefor of bit rot occurs.

> I still like Vagrant. But I believe it's yet another victim of the Hashicorp license change debacle from a year or two ago.

The license change is irrelevant - from the licensing page:

> All non-production uses are permitted.

Devs who use Vagrant in a development environment can do it as they used to do it before.

> The latest open source version is still available on the Ubuntu repo, but who knows who long it will work until somefor of bit rot occurs.

Hashicorp products have always been intended to be downloaded from the website, since they're statically linked binaries (I don't like that they're huge, but matter of factually, they make distribution trivial).

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#213

Earlier quoted context omitted.

(I deleted a comment that didn't seem relevant any more now that you added a bunch.) So it's okay to blame vets of Unit 8200 for its actions 10 years after they founded Snyk (I have no idea how long after they left the unit) on the grounds that the intelligence arm of the IDF doesn't name names? So just in case and in the face of all the facts of the timelines, we should make sure to drag out these people's former ma…

Yes, because it's an institutional problem. I'm sure you have no issues using products developed by say, ex FSB agents just because it's been 10 years?

The FSB is no comparison because it's more equivalent to the NSA—it was a career path, not a place to serve out mandatory military service.

FSB agents worked there for decades and chose that instead of any number of other things they could have done. Unit 8200 conscripts worked there for at most 2 years 8 months and chose it instead of a different, more gun-blazing branch of the military.

Mandatory military service completely changes the profile of the vets in a way that makes all these comparisons totally irrational. They're founded in fear and hatred for Israelis, not any reasonable similarity.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#214
Hopefully this makes the Cursor team reconsider security (which doesn't seem very good really).

Stopped using it for serious stuff after I noticed their LLMs grabs your whole .env files and sends them to their server... even after you add them to their .cursorignore file. Bizarre stuff.

Now imagine a bad actor exploiting this... recipe for disaster.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#217
post #208
post #193

Earlier quoted context omitted.

Cursor does not have a bug bounty though, and its hard to see how this constitutes anything other than a direct attack on them, their users, or both. "The incentive structure made me do it" does not justify acting like a criminal.

> Cursor does not have a bug bounty Shouldn't this alone be considered criminal negligence at this point? Cursor isn't some random open source project. It's a company that has funding, and subscriptions. Hell, I pay Cursor for a monthly subscription. Pretty incredible that they have no bounty program.

The lack of a bug bounty program doesn't prohibit them from rewarding reported vulnerabilities.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#218

Hopefully this makes the Cursor team reconsider security (which doesn't seem very good really). Stopped using it for serious stuff after I noticed their LLMs grabs your whole .env files and sends them to their server... even after you add them to their .cursorignore file. Bizarre stuff. Now imagine a bad actor exploiting this... recipe for disaster.

Security often means the opposite of scalability and growth, so why should they? The business goal is to make sure Cursor grows large enough that they have economics of scale to be a viable business.

If you want secure LLM you can use Mistral, which comes with all the EU limitations, good and bad.

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#219
post #77

Earlier quoted context omitted.

The real problem is video performance in VMs. It still just...kind of sucks. Running Cinnamon in a VM is just about impossible to get GL acceleration working properly. nvidia gates it's virtualized GPU offerings behind their enterprise cards, so we're left with ineffective command translation. IMO: I can tolerate just about every other type of VM overhead, but choppy/unresponsive GUIs have a surprisingly bad ergonomi…

But would it matter much for development? Either SSH into the VM and use vi/emacs or use an IDE/editor with remote support. VS Code even lets you use a container as a development environment (I know, not a VM by default): https://code.visualstudio.com/docs/devcontainers/containers

I don't know about VS Code's dev containers extension but the SSH extension's README says:

> Using Remote-SSH opens a connection between your local machine and the remote. Only use Remote-SSH to connect to secure remote machines that you trust and that are owned by a party whom you trust. A compromised remote could use the VS Code Remote connection to execute code on your local machine.

https://marketplace.visualstudio.com/items?itemName=ms-vscod...

If you're worried about extensions there's also:

> When a user installs an extension, VS Code automatically installs it to the correct location based on its kind. If an extension can run as either kind, VS Code will attempt to choose the optimal one for the situation;

https://code.visualstudio.com/api/advanced-topics/remote-ext...

Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com

#220
post #113

Earlier quoted context omitted.

Just a reminder that Unit 8200 is staffed mostly by conscripts who are serving out their mandatory military service and chose to accept an invitation to serve in the cyberwarfare arm of the IDF instead of choosing to shoot guns. In other words, it's staffed by Israeli kids who made the choice most of us would have made under the circumstances. It seems a bit unfair to hold that against them more than 10 years later,…

> In other words, it's staffed by Israeli kids who made the choice most of us would have made under the circumstances. It seems a bit unfair to hold that against them more than 10 years later, no? You could say the same about the guy in a call center in India trying to pull a tech support scam on you over the phone. Yes, he's probably making the best choice he can for his own livelihood, probably the same thing you w…

> You could say the same about the guy in a call center in India trying to pull a tech support scam on you over the phone. Yes, he's probably making the best choice he can for his own livelihood, probably the same thing you would do in his position. No, that doesn't mean you should trust him.

No, you can't, because the scammer in the call center is choosing that over thousands of other options. Are they choosing to maximize their pay? Maybe. But for every scammer there are thousands of Indians who show a different option.

Choosing to dodge or resist the draft is totally different—very few people do it, and those who do get prison terms. If you sincerely believe that you'd have chosen to go to prison rather than be drafted, more power to you, but I and most others would aim to minimize the likelihood of ourselves dying and minimize the number of people I'd have to kill. For me that would have meant signing up for cyberwarfare, which in Israel would have meant Unit 8200.

The rest of your comment is totally irrational fear-based speculation. Anti-Israel sentiment may not be antisemitic, but it sure shares the same tendency towards irrational fear and aggression.

Post reply on HN