Someone bought 30 WordPress plugins and planted a backdoor in all of them
251–260 of 368 posts
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#252Earlier quoted context omitted.
Lockfiles help more than people realize. If you're pinned and not auto-updating deps, a package getting sold and backdoored won't hit you until you actually update. The scarier case is Dependabot opening a "patch bump" PR that probably gets merged because everyone ignores minor version bumps.
I wish those PRs made by the bot can have a diff of the source code of those upgraded libraries (right in the PR, because even if in theory you could manually hunt down the diffs in the various tags...in practise nobody does it).
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#253This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. We've built our existing tech stacks and corporate governance structures for a different era. If you want to credit one specifi…
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#254Earlier quoted context omitted.
That's the point I am making, and the point of asking "what is the alternative" Developers aren't alone in adhering to schedules. Many folks in many roles do it. All deal with missed deadlines, success, expectation management, etc. No one operates in magical no-timeline land unless they do not at all answer to anyone or any user. Not the predominant model, right? So rather than just say "you can blame the PMs" I'd lo…
Software release dates are so arbitrary though. We no longer make physical media that needs time to make and ship. Why does software need to be released on February 15th instead of March 7th?
Because it has to be released at some point, and without picking a point in advance, you can never reach it.
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#255This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. We've built our existing tech stacks and corporate governance structures for a different era. If you want to credit one specifi…
Well, Cryptocurrencies are part of said new era. They aren't strictly a problem that made things worse: they're a technology that comes with tradeoffs. The cat is out of the bag and we have to design around technologies that are here to stay in whatever capacity. Distributed, cryptography-based currencies/tokens are one of those technologies.
I don't know the statistics, but it seems like it's way more profitable for the grifters to target other grifters instead of taking over my machines and extorting me. Or maybe I just got lucky.
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#256Earlier quoted context omitted.
It works like any other case of liability. If the seller is in the US, the seller is held liable if they transfer to a foreign entity who isn't accountable to US laws (because the user/customer would have no recourse if the buyer does something evil). Opposite is true if the buyer is in the US. If only the user is in the US, there's not much they can do but use the courts or politicians to try to get justice overseas…
So you want people who sell a business to be open to liability for things that the new owner does? Don't you see what kind of negative consequences that would have?
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#257Earlier quoted context omitted.
No, data exfiltration is just as lucrative as crypto. We are unfortunately long past the point where viruses would frequently be merely annoying.
Just about every exploited site I've had to deal with has been some form of crypto miner.
That doesn't mean it's the most lucrative revenue stream.
Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#258Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them
#259This somehow reminds me of the irony that was Secure Custom Fields: https://news.ycombinator.com/item?id=41821336