Earlier quoted context omitted.
I’m dropping as many as I can as is my prerogative as a consumer.
Do you need some help with that? I'll be more than happy if antisemites like you won't be using any of the advanced tech we're working hard to create .
Snyk security researcher deploys malicious NPM packages targeting cursor.com
321–330 of 331 posts
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#322Earlier quoted context omitted.
No one is entitled to my business. I have no cognitive dissonance, my business interests are aligned with my moral interests in this case. I don’t use Israeli tech whenever possible. You “denouncing” people who make a rational calculation isn’t really helping to market the firms you are supporting.
I'm not supporting firms, I'm supporting the right of individuals to be seen as individuals rather than as members of a group assigned to them at birth. That said, this obviously isn't going anywhere, so have a nice day.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#323Earlier quoted context omitted.
Do you need some help with that? I'll be more than happy if antisemites like you won't be using any of the advanced tech we're working hard to create .
Ah the old trick of calling racism if you voice disagreement with a government… At this point people like you have made the word "antisemite" completely devoid of any meaning.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#324Earlier quoted context omitted.
Ah the old trick of calling racism if you voice disagreement with a government… At this point people like you have made the word "antisemite" completely devoid of any meaning.
You are not criticizing the government but denying Israel's right to exists and protect itself, and this is the good ol' antisemitism with a brand new liberal mask.
If you don't criticise this, you are a terrible human being.
Genocide is bad also if you do it on dark skinned people, FYI.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#325Earlier quoted context omitted.
> Conspiracies Not when the dissidents put their name to paper. We, veterans of Unit 8200, reserve soldiers both past and present, declare that we refuse to take part in actions against Palestinians and refuse to continue serving as tools in deepening the military control over the Occupied Territories. It is commonly thought that the service in military intelligence is free of moral dilemmas and solely contributes to…
It's signed by 34 people… I guess we can say it's completely irrelevant.
There weren't many Oskar Schindlers either.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#326[EDIT: See the response by a Cursor dev below — looks like it was not authorized by them] Sounds to me like Cursor internally has a private NPM registry with those packages. Because of how NPM works, it's quite easy to trick it to fetch the packages from the public registry instead, which could be used by an attacker [0]. Assumably, this Snyk employee either found or suspected that some part of Cursor's build is misc…
Hey there! I run DevRel & SecRel @ Snyk, we just published a piece to help dispel all the rumors, etc. This provides a lot of in-depth info on the situation: https://snyk.io/blog/snyk-security-labs-testing-update-curso...
Who did the GDPR review before extracting env vars from systems that were not under your control? How did actively extracting potentially private data from the environment not get flagged as Unauthorized Access?
If this "experiment" (which happened to be against a competitor, mind) was reviewed and approved internally, that is a great demonstration of Snyk's approach to (ir)responsible data collection and disclosure.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#327Earlier quoted context omitted.
This response doesn't make a lot of sense. What's the justification for taking all of the environment variables? This post tries to paper over that particular problem. If your goal was to see if you could attack the dependency chain the first steps of user+hostname would have been sufficient to prove your case. Taking the environment variables is about taking the secrets, and kind of moves this from PoC to opposition…
Frankly I wouldn't be surprised if this was a case of Hanlon's razor. Some "researcher" thought well ENV vars will certainly show us what we want and that's where the conversation ended without thinking a little harder into what else might be in the vars.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#328Earlier quoted context omitted.
You are not criticizing the government but denying Israel's right to exists and protect itself, and this is the good ol' antisemitism with a brand new liberal mask.
The population of Gaza has LITERALLY been decimated in the past year (10% died). If you don't criticise this, you are a terrible human being. Genocide is bad also if you do it on dark skinned people, FYI.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#329Earlier quoted context omitted.
The population of Gaza has LITERALLY been decimated in the past year (10% died). If you don't criticise this, you are a terrible human being. Genocide is bad also if you do it on dark skinned people, FYI.
So had the population of Drezden in 1945. If you can't understand that being on the evil side of history and starting a war has its price, you are a terrible human being.
Dresden was a war crime and played no part in winning the war. Same with the atomic bombs.
Re: Snyk security researcher deploys malicious NPM packages targeting cursor.com
#330Earlier quoted context omitted.
it's many more keypresses, and using modifier keys is generally rsi-prone
Without commenting on this subthread (I don't have an opinion), you or anyone else with this concern should look into sticky modifiers (modifiers that apply to the next key press without being held). They were a game changer for me personally as far as managing RSI, as I had a bad habit of tilting my wrist to eg type a capital T.