Live data from Hacker News

NPM won't publish packages containing the word keygen

mamot.fr

231–240 of 269 posts

Re: NPM won't publish packages containing the word keygen

#231

keyword moderation is terrible and only affects the language(s) you know about. It doesn't actually prevent the content (the goal of these types of filters) from being served. It'd be like a virus scanner preventing a program from running because it had the name 'virus' in it ... which would prevent itself from running -- probably.

I love keyword moderation. I love finding ways to demonstrate to those using it that it's futile by using only non-offensive words to thoroughly offend people. I was given a talking-to by a game administrator once for naming a match "Your granny rides my throbbing purple rod." It didn't contain any no-no words, though!

Re: NPM won't publish packages containing the word keygen

#232
post #5

NPM is owned by Microsoft, who sell proprietary software, the kind that keygens are made to defeat. Don't expect to see KMS spoofers on GitHub anytime soon for the same reason.

What about this? https://github.com/massgravel/Microsoft-Activation-Scripts

Those are scripts that talk to KMS servers on the internet - they would not fall under DMCA prohibitions on anticircumvention as I understand it.

KMS spoofers are the services running on those internet hosts the scripts talk to.

py-kms is on GitHub but I assume it won't remain there for the same reasons as yt-dlp.

Re: NPM won't publish packages containing the word keygen

#233
post #232

Earlier quoted context omitted.

What about this? https://github.com/massgravel/Microsoft-Activation-Scripts

Those are scripts that talk to KMS servers on the internet - they would not fall under DMCA prohibitions on anticircumvention as I understand it. KMS spoofers are the services running on those internet hosts the scripts talk to. py-kms is on GitHub but I assume it won't remain there for the same reasons as yt-dlp.

> py-kms is on GitHub but I assume it won't remain there for the same reasons as yt-dlp.

You mean this yt-dlp that isn't on there? https://github.com/yt-dlp/yt-dlp

That script also does more than just Online KMS activation, which would be clear from a few seconds skimming.

There's also been no indication that any of these repos would get taken down. At all. py-kms has been there since 2017. You'd think if Microsoft had such a big problem with its existence, it'd have gotten pulled in the last 6 years.

Re: NPM won't publish packages containing the word keygen

#235
post #168

Earlier quoted context omitted.

I only recently learned that my username for 20 years has "orgy" in it, and I've been getting blocked by many games

20+ years of this handle online without problems, and I found out trying to sign up for Stern Pinball Insider that "bint" is a dirty word: https://en.wiktionary.org/wiki/bint

“I mean, if I went 'round saying I was an emperor, just because some moistened bint had lobbed a scimitar at me, they'd put me away!”

Re: NPM won't publish packages containing the word keygen

#236
post #64

Earlier quoted context omitted.

That sounds completely different. Blocking the word 'keygen' accomplishes absolutely nothing and is clearly stupid. Blocking build scripts absolutely stops a major attack vector.

Malicious unchecked code in postinstall can just be moved to runtime so blanket blocking postinstall is as effective a solution to supply chain attacks as the solution of blocking npm packages with the word "keygen" in them is to the problem of .... js based keygens??? There are many legitimate purposes for postinstall scripts yet the anti-postinstall crowd acts like they solved security issues with this one easy ste…

> moved to runtime

So a completely different scenario? Let's assume for a moment that developers only ever 'build' or 'check' their code, but all actual runtime behavior is in production. In production we have toooooons of security tooling for monitoring and constraining program behavior. On dev computers? Basically nothing.

Of course, developers run `test` as well, and sometimes they run the whole program but these use cases, especially at companies, are increasingly moving to CI.

Re: NPM won't publish packages containing the word keygen

#237

Earlier quoted context omitted.

Dirty word in the context of security, copyright liability, etc.

Ah yes, the age-old hacking tool: ssh-keygen.

Just learned "keygen" is the term the script-kiddies use to describe the act of generating fake activation keys. Never let it be said HN is not educational. But I feel the same way I felt when I noticed idiots using "crypto" to refer to cryptocurrency instead of cryptography.

Re: NPM won't publish packages containing the word keygen

#238

Earlier quoted context omitted.

> musical accompaniments Can someone please explain this to me?

back in the old days, keygens were a way for hacking groups to show off, so they had cool graphics and played music.

| back in the old days

Thank you for my daily memento morì.

Re: NPM won't publish packages containing the word keygen

#239
post #138

Earlier quoted context omitted.

Yeah what was it about keygens always having the most unhinged synth soundtracks

It's part of the demoscene culture, which overlaps a lot https://en.wikipedia.org/wiki/Demoscene

https://files.scene.org/
Post reply on HN