Live data from Hacker News

Someone bought 30 WordPress plugins and planted a backdoor in all of them

anchor.host

251–260 of 368 posts

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#252
post #215

Earlier quoted context omitted.

Lockfiles help more than people realize. If you're pinned and not auto-updating deps, a package getting sold and backdoored won't hit you until you actually update. The scarier case is Dependabot opening a "patch bump" PR that probably gets merged because everyone ignores minor version bumps.

I wish those PRs made by the bot can have a diff of the source code of those upgraded libraries (right in the PR, because even if in theory you could manually hunt down the diffs in the various tags...in practise nobody does it).

No need to hunt it down, there's a URL in the PR / commit message that links to the full diff.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#253

This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. We've built our existing tech stacks and corporate governance structures for a different era. If you want to credit one specifi…

Obligatory: https://xkcd.com/538/

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#254
post #178

Earlier quoted context omitted.

That's the point I am making, and the point of asking "what is the alternative" Developers aren't alone in adhering to schedules. Many folks in many roles do it. All deal with missed deadlines, success, expectation management, etc. No one operates in magical no-timeline land unless they do not at all answer to anyone or any user. Not the predominant model, right? So rather than just say "you can blame the PMs" I'd lo…

Software release dates are so arbitrary though. We no longer make physical media that needs time to make and ship. Why does software need to be released on February 15th instead of March 7th?

> Why does software need to be released on February 15th instead of March 7th?

Because it has to be released at some point, and without picking a point in advance, you can never reach it.

https://en.wikipedia.org/wiki/Parkinson%27s_law

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#255

This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. We've built our existing tech stacks and corporate governance structures for a different era. If you want to credit one specifi…

Well, Cryptocurrencies are part of said new era. They aren't strictly a problem that made things worse: they're a technology that comes with tradeoffs. The cat is out of the bag and we have to design around technologies that are here to stay in whatever capacity. Distributed, cryptography-based currencies/tokens are one of those technologies.

Crypto has been an awful development in many ways, but I happily welcome it when it has made malware so much more benign to me. The last malware that affected me personally was a crypto miner worm, and the one before that was a crypto wallet stealer, neither of which affects me at all as I don't meddle with crypto.

I don't know the statistics, but it seems like it's way more profitable for the grifters to target other grifters instead of taking over my machines and extorting me. Or maybe I just got lucky.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#256

Earlier quoted context omitted.

It works like any other case of liability. If the seller is in the US, the seller is held liable if they transfer to a foreign entity who isn't accountable to US laws (because the user/customer would have no recourse if the buyer does something evil). Opposite is true if the buyer is in the US. If only the user is in the US, there's not much they can do but use the courts or politicians to try to get justice overseas…

So you want people who sell a business to be open to liability for things that the new owner does? Don't you see what kind of negative consequences that would have?

I meant to hold the seller liable if they do not follow a due diligence process. But actually the liability you mean also exists. The two are called direct liability and vicarious liability.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#257

Earlier quoted context omitted.

No, data exfiltration is just as lucrative as crypto. We are unfortunately long past the point where viruses would frequently be merely annoying.

Just about every exploited site I've had to deal with has been some form of crypto miner.

Sure, because there's no reason not to, and because crypto mining is noisier than data exfiltration.

That doesn't mean it's the most lucrative revenue stream.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#258
post #71
post #51

[flagged]

I think you're behind the times, you need to replace "crypto" with "AI" now.

Amusingly he’s one step ahead of you, see the link to his website above - it has crypto and AI agents.
Post reply on HN