🤩 Exciting news! I'm ready to share the project I've been working on for the past 2 months.
✨ Wormhole – the fastest way to send files ✨
Wormhole lets you share files with end-to-end encryption and it's super fast.
Send a file in just 2 seconds: https://wormhole.app
🙌 Just released a CLI tool called `thanks` to help you thank the open source maintainers you depend on! ✨
1. Run 'npx thanks' in your project
2. See which of your dependencies are seeking donations! 💸🌟 Open source authors, add yourself to the list: https://github.com/feross/thanks
I wish more developers understood the constant stream of malware that is posted to npm, PyPI, and all package managers...
Here's just a taste of some crazy malware Socket identified in the past couple weeks...
All malware descriptions were FULLY WRITTEN by Socket AI.
"someone transferred ~0.05 BTC (currently ~$900), paying 0.01 BTC in fees (currently ~$180)
and the network burned enough electricity for that single transaction to drive a Model S well over 1000km, or power an average house in Germany for about a month"
–
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months!
Introducing ✨ Socket ✨⚡️ Search millions of open source packages
🔒 Detect suspicious package updates in real-time
🛡 Block software supply chain attacks
is using ChatGPT to examine every npm and PyPI package for security issues!
🤯 In just 2 days, we confirmed 227 vulnerable and malware packages, all discovered with the help of ChatGPT
I taught a web security course at Stanford. All the course materials, slides, and videos are freely available online. If you want to learn about secure web programming, this course is for you! ✨📝 Website: https://cs253.stanford.edu📺 YouTube playlist:
to marry me was the easiest decision I've ever made! ❤️ If you know Noor, then you know what I mean! I feel lucky that I get to spend my life with her.
But planning the proposal wasn't simple. Here's how I asked her to marry me...
1/5
This video of Steve Jobs introducing Wi-Fi is incredible.
He's casually browsing the web, then he suddenly picks up the laptop and everyone in the audience realizes that it's not plugged into anything and they go crazy with cheers and applause!
11 Mbps!
🌟 Lazy-loading images and iframes are coming to the web platform and I'm excited that this will soon be possible:
<img lazyload='on' src='cool.jpg' />
<iframe lazyload='on' src='cool.html' />
Check the issue on whatwg/html:
Now that Apple has willingly built spyware into iOS and macOS, within 10 years this tech will:
(1) be mandated by government in all end-to-end encrypted apps; and
(2) expand to scan for terrorism, disinformation, "misinformation", then eventually political images and memes.
1/5
I’m ending the `npm install funding` experiment I introduced a few days ago.
I appreciate the thoughtful discussion and feedback from the community. I shared some thoughts about how the experiment went from my perspective:
).
⭐️ This funding fuels our mission to make open source safer for everyone!
🚀🚀🚀 We're also announcing 4 new products this week as part of Socket Launch Week! ✨🧵 1/10
Sweet! When you run `npm publish`, the latest npm 6.0.0 shows which files are included in the package as well as total package size! ✨
Should help prevent sensitive or huge files from getting included by accident. This is a great change. 💪
Shrink those packages!
I just built a site to help you make a friend in 2 minutes! My goal is to help people stuck indoors because of COVID-19 (or police curfews) to make meaningful connections with strangers. Hope you love it!
https://virus.cafe
🗣 Big news! Today I'm launching a Patreon! ✨
I need your help to continue making free software like WebTorrent ❤️ and Standard 🌟. If you use any of my 100+ open source projects, please support my ongoing work by becoming a patron. 😇https://patreon.com/feross
This is brilliant.
Make public transit free ➡️ increased public transit usage (obviously) ➡️ decreased congestion, fewer travel delays ➡️ increased economic activity, more eating out, better quality of life ➡️ more tax revenue to fund the free transit
✨🇪🇪✨
Following a successful five year pilot in its capital, Estonia is set to become the first country in the world to make public transport free everywhere, for everyone.
https://popupcity.net/estonia-to-become-the-worlds-first-free-public-transport-nation/…
This Thanksgiving, I'm thinking of the open source maintainers who make all my work possible. Linux, BSD, GNU, Git, nginx, Node.js, Chromium, Firefox, and literally thousands of npm packages.
I stand on the shoulders of giants.
💥 Want to find out if the compromised ESLint dependency is on your machine?
⚡️ Just run this:
cd ~/code
find . -type d -name "eslint-scope" -print0 | xargs -n 1 -0 -I % sh -c "(cat %/package.json | npx json version) && echo '(at %)'"
Look for "3.7.2" in the output ☠️
"This man has been editing a Wikipedia article every four minutes for 13 years. He is insane, and he has had a huge impact on what you and I read every day when we need more information about literally anything"
I've been testing #GitHubCopilot in Alpha for the past two weeks. Some of the code suggestions it comes up with are eerily good.
Here's a thread with some examples that I found surprising. Will update with new examples over time.
Get the JavaScript Source Code CD Professional Series for only $2.99
Almost 800 ready-to-use JavaScripts that you can cut & paste into your own HTML documents!
🤯 Just read a fascinating paper called "The Surprising Creativity of Digital Evolution"
🤣 It's a bunch of HILARIOUS anecdotes showing how Artificial Life systems often produce SUPER surprising and SHOCKINGLY ridiculous results. 😲👇 THREAD
Do you use my open source software at work? I now offer an open source support contract.
- 4 hours of consulting (development, bug fixes, etc.) per month
- Email support
- Company logo on readmes + website (~180K views/mo)
- Priority GitHub issues
🌟
☠️ Passwords ☠️
- Average user has ~100 accounts
- Creates 50 passwords per year
- High rate of password re-use (75% of users)
- Frequent password sharing with others (40% of users)
- Huge number of password resets (40%-60% reset every 3 months)
Source: Nikola Blanchard
Family subscription and let the credit card lapse. She didn't notice the emails asking to update the card.
1Password completely deleted her account and logged her out on all devices. Now she can't access her 100+ passwords and 2FA tokens
WTF
I added some improvements to The Annoying Site
- Change theme-color in a loop (Safari 15)
- Picture-in-picture in all browsers
- Block close window better
- Animate URL with emojis
- Pointer lock
- Request MIDI, bluetooth, USB, serial, HID
⚠️ Warning ⚠️https://theannoyingsite.com
US cell carriers are selling access to your real-time phone location data https://zdnet.com/article/us-cell-carriers-selling-access-to-real-time-location-data/… There's even a try-before-you-buy page where you can track the location of your own phone: https://locationsmart.com/try/
If you have a website, definitely check out your site's Chrome UX Report. It's a bit tricky to set up (watch the embedded video), but when you're done you get an automatically updating dashboard with real user experience numbers! Cool!
https://developers.google.com/web/updates/2018/08/chrome-ux-report-dashboard… h/t
Some of the most innovative open source software within the JavaScript ecosystem has been produced by eccentric, independent individuals who write open source because they love it, not because some megacorp pays them to do it while representing the company's interests. 1/2
🗺 Google Map's Moat – How far ahead of Apple Maps is Google Maps?
https://justinobeirne.com/google-maps-moat…
One of the best tech articles I've read in a while. Not kidding – Google's work on Maps is awe inspiring. It's hard to imagine the scale that they're operating at.
This is not a drill.
Police are already misusing location data gathered for COVID contact tracing even though everyone SWORE it wouldn't be used for anything by health purposes.
Once the data and tools exist, governments can’t help themselves – it’s just too tempting.
2/5
🚀 BIG NEWS 🚀
Wormhole now has ✨ QR Codes ✨✅ Send files from desktop to mobile with *one click*
✅ End-to-end encryption keeps your files private
✅ Works on all platforms – iOS, Android, Mac, Windows, Linux, Chromebook – anything!
Try it out now! https://wormhole.app
Just got the news that I've been selected as a #GitHubStar for 2023 and I couldn't be more thrilled! Looking forward to continuing to help other developers and to contribute to the open source community 🚀🌟❤️
Real Mac bug for 10+ years: "In some cases the audio balance may unexpectedly drift towards the left or right channel. This can happen if you rapidly press the volume up or down keys while the computer's microprocessor is under heavy load"
Still not fixed https://support.apple.com/kb/TA22305?locale=en_US…
Ran into a spectacularly awful Safari bug in the latest Safari (14.1.1 on macOS and iOS 14.6).
Opening an IndexedDB database fails 100% of the time on the first try. 😩
If you refresh, it starts working.
Bug report: https://bugs.webkit.org/show_bug.cgi?id=226547…
cc
.
The short-sightedness is staggering. How can they think governments won't demand to expand this?
Before today, I believed that Apple genuinely cared about my privacy. But no more.
This is a disaster.
5/5
for the next 12 months as a 🌟 Platinum Sponsor!
🦁 Brave is a browser with your interests at heart — https://brave.com🤩 Thanks to the awesome people at Brave for supporting open source! ✨
about why some developers are avoiding app store headaches by going web-only.
“We want to be an example of what a modern, fast web app can do,” he says. “And we want to blow a few minds while we’re at it.”
The company I started – Socket Inc – has a snazzy new home on the web: https://socket.dev
If you want to work with me and help build cool software like
If these creative and brilliant folks could make a decent living writing open source software to benefits the commons instead of seeking private contracts writing proprietary code for a single company, we'd all have more innovative open source software to use. Everyone wins. 2/2
Wow, security is SUPER HARD. 😫It's possible to make always-on voice assistants like Amazon Echo, Google Home, and Siri silently place a phone call from 5 feet away using ultrasound https://youtube.com/watch?v=21HjF4A3WE4…
Chakra UI is the best frontend component library, hands down.
If you haven't used it, you're missing:
- Components are beautiful by default
- Accessible HTML
- Responsive maintainers
- Active community
- Thoughtful and delightful API design
I'm a huge, huge fan
Happy to announce that the Wormhole cryptography code is now open source!
✅ MIT License
✅ $1,000 bounty for finding a security issue (https://wormhole.app/security/disclosure…)
Check it out here:
This code is using curl to send the contents of the file '/etc/passwd' to a remote server. This is a highly suspicious and potentially malicious behavior as it could cause sensitive data to be sent to an attacker's server.
https://socket.dev/npm/package/segment-bundle/files/6.6.9/package.json…
I was an engineer intern on the Facebook Groups team, 10 years ago today. Groups was one of the most successful Facebook products of all time and we built it in ~5 months with ~5 full-time and 2 interns.
Easily the best job I’ve ever had https://twitter.com/boztank/status/1313680402112888835…