Opens profile photo
Follow
Click to Follow feross
Feross
@feross
✨ Founder + CEO (socket.dev) • 🌲 Stanford lecturer (cs253.stanford.edu) • ❤️ Open source at + 🧙‍♂️ Mad scientist
EntrepreneurStanford, CAfeross.orgJoined August 2008

Feross’s posts

🤩 Exciting news! I'm ready to share the project I've been working on for the past 2 months. Wormhole – the fastest way to send files Wormhole lets you share files with end-to-end encryption and it's super fast. Send a file in just 2 seconds: wormhole.app
138
3,172
🙌 Just released a CLI tool called `thanks` to help you thank the open source maintainers you depend on! 1. Run 'npx thanks' in your project 2. See which of your dependencies are seeking donations! 💸 🌟 Open source authors, add yourself to the list: github.com/feross/thanks
Embedded video
GIF
52
2,580
I wish more developers understood the constant stream of malware that is posted to npm, PyPI, and all package managers... Here's just a taste of some crazy malware Socket identified in the past couple weeks... All malware descriptions were FULLY WRITTEN by Socket AI.
46
2,815
"someone transferred ~0.05 BTC (currently ~$900), paying 0.01 BTC in fees (currently ~$180) and the network burned enough electricity for that single transaction to drive a Model S well over 1000km, or power an average house in Germany for about a month" – 
Image
46
1,322
🚀 Exciting news! I'm ready to share the project I've been working on for the past 7 months! Introducing Socket ⚡️ Search millions of open source packages 🔒 Detect suspicious package updates in real-time 🛡 Block software supply chain attacks
72
1,309
HUGE NEWS! 🤖 Introducing Socket AI – ChatGPT-Powered Threat Analysis is using ChatGPT to examine every npm and PyPI package for security issues! 🤯 In just 2 days, we confirmed 227 vulnerable and malware packages, all discovered with the help of ChatGPT
35
1,214
I'm engaged! Asking to marry me was the easiest decision I've ever made! ❤️ If you know Noor, then you know what I mean! I feel lucky that I get to spend my life with her. But planning the proposal wasn't simple. Here's how I asked her to marry me... 1/5
Image
Image
Image
117
974
This video of Steve Jobs introducing Wi-Fi is incredible. He's casually browsing the web, then he suddenly picks up the laptop and everyone in the audience realizes that it's not plugged into anything and they go crazy with cheers and applause! 11 Mbps!
11
777
🌟 Lazy-loading images and iframes are coming to the web platform and I'm excited that this will soon be possible: <img lazyload='on' src='cool.jpg' /> <iframe lazyload='on' src='cool.html' /> Check the issue on whatwg/html:
7
742
Now that Apple has willingly built spyware into iOS and macOS, within 10 years this tech will: (1) be mandated by government in all end-to-end encrypted apps; and (2) expand to scan for terrorism, disinformation, "misinformation", then eventually political images and memes. 1/5
18
673
Replying to
Every line of code in that screenshot is explicit and quite understandable. If the alternative is a magical and overly-clever framework, I'll pass.
9
661
200,000+ successful flights were completed in a single day, on July 4th, 2018. What impressive engineering, coordination, and human ingenuity!
Embedded video
GIF
9
604
🚀 Huge news! has raised $20M Series A funding led by Andreessen Horowitz (). ⭐️ This funding fuels our mission to make open source safer for everyone! 🚀🚀🚀 We're also announcing 4 new products this week as part of Socket Launch Week! 🧵 1/10
54
597
Sweet! When you run `npm publish`, the latest npm 6.0.0 shows which files are included in the package as well as total package size! Should help prevent sensitive or huge files from getting included by accident. This is a great change. 💪 Shrink those packages!
Image
8
485
I just built a site to help you make a friend in 2 minutes! My goal is to help people stuck indoors because of COVID-19 (or police curfews) to make meaningful connections with strangers. Hope you love it! virus.cafe
38
463
🗣 Big news! Today I'm launching a Patreon! I need your help to continue making free software like WebTorrent ❤️ and Standard 🌟. If you use any of my 100+ open source projects, please support my ongoing work by becoming a patron. 😇 patreon.com/feross
Image
14
465
There are more books for sale on Amazon from the 1880’s than the 1980’s. The missing books are out-of-print but still copyrighted. Insane!
Image
15
421
This is brilliant. Make public transit free ➡️ increased public transit usage (obviously) ➡️ decreased congestion, fewer travel delays ➡️ increased economic activity, more eating out, better quality of life ➡️ more tax revenue to fund the free transit 🇪🇪
Quote
Following a successful five year pilot in its capital, Estonia is set to become the first country in the world to make public transport free everywhere, for everyone. popupcity.net/estonia-to-bec
Image
14
426
Big news! I’m going for my CS master’s degree at Stanford. 🎓 One of my goals is to teach a class on Web Apps – we’ll see how that goes!
15
438
This Thanksgiving, I'm thinking of the open source maintainers who make all my work possible. Linux, BSD, GNU, Git, nginx, Node.js, Chromium, Firefox, and literally thousands of npm packages. I stand on the shoulders of giants.
3
421
Top way to become a better programmer: BE LESS CLEVER. Your cleverness is just going to cause you (and probably me) pain later...
9
374
💥 Want to find out if the compromised ESLint dependency is on your machine? ⚡️ Just run this: cd ~/code find . -type d -name "eslint-scope" -print0 | xargs -n 1 -0 -I % sh -c "(cat %/package.json | npx json version) && echo '(at %)'" Look for "3.7.2" in the output ☠️
14
383
I've been testing #GitHubCopilot in Alpha for the past two weeks. Some of the code suggestions it comes up with are eerily good. Here's a thread with some examples that I found surprising. Will update with new examples over time.
Quote
Meet GitHub Copilot - your AI pair programmer. copilot.github.com
5
354
Get the JavaScript Source Code CD Professional Series for only $2.99 Almost 800 ready-to-use JavaScripts that you can cut & paste into your own HTML documents!
Image
Image
17
362
🤯 Just read a fascinating paper called "The Surprising Creativity of Digital Evolution" 🤣 It's a bunch of HILARIOUS anecdotes showing how Artificial Life systems often produce SUPER surprising and SHOCKINGLY ridiculous results. 😲 👇 THREAD
Embedded video
GIF
7
321
1/ Ryan Dahl (creator of Node.js) wrote an epic rant and then quit writing software for a while. I want to repost it here now.
10
300
☠️ Passwords ☠️ - Average user has ~100 accounts - Creates 50 passwords per year - High rate of password re-use (75% of users) - Frequent password sharing with others (40% of users) - Huge number of password resets (40%-60% reset every 3 months) Source: Nikola Blanchard
10
291
My friend has a Family subscription and let the credit card lapse. She didn't notice the emails asking to update the card. 1Password completely deleted her account and logged her out on all devices. Now she can't access her 100+ passwords and 2FA tokens WTF
27
293
I added some improvements to The Annoying Site - Change theme-color in a loop (Safari 15) - Picture-in-picture in all browsers - Block close window better - Animate URL with emojis - Pointer lock - Request MIDI, bluetooth, USB, serial, HID ⚠️ Warning ⚠️ theannoyingsite.com
13
288
It gets worse! Someone found a bug in the try-before-you-buy demo page. You could type in any U.S. phone number and get the phone’s real-time location *without any text to the user for permission*. 200 million people exposed! What. The. Hell. zdnet.com/article/cell-p
Quote
US cell carriers are selling access to your real-time phone location data zdnet.com/article/us-cel 😯 There's even a try-before-you-buy page where you can track the location of your own phone: locationsmart.com/try/
Image
Image
5
259
Some of the most innovative open source software within the JavaScript ecosystem has been produced by eccentric, independent individuals who write open source because they love it, not because some megacorp pays them to do it while representing the company's interests. 1/2
4
237
Replying to
This is not a drill. Police are already misusing location data gathered for COVID contact tracing even though everyone SWORE it wouldn't be used for anything by health purposes. Once the data and tools exist, governments can’t help themselves – it’s just too tempting. 2/5
8
239
🚀 BIG NEWS 🚀 Wormhole now has QR Codes Send files from desktop to mobile with *one click* End-to-end encryption keeps your files private Works on all platforms – iOS, Android, Mac, Windows, Linux, Chromebook – anything! Try it out now! wormhole.app
9
222
Replying to and
Also, you're comparing apples to oranges. Express is low-level and un-opinionated. It's not trying to solve the same problems as Rails.
4
218
Replying to
I'm incredibly disappointed that this was approved and built by . The short-sightedness is staggering. How can they think governments won't demand to expand this? Before today, I believed that Apple genuinely cared about my privacy. But no more. This is a disaster. 5/5
Image
8
217
🙌 HUGE THANKS to who just announced they are supporting for the next 12 months as a 🌟 Platinum Sponsor! 🦁 Brave is a browser with your interests at heart — brave.com 🤩 Thanks to the awesome people at Brave for supporting open source!
Image
6
201
I'm quoted in about why some developers are avoiding app store headaches by going web-only. “We want to be an example of what a modern, fast web app can do,” he says. “And we want to blow a few minds while we’re at it.”
Image
5
214
React is Considered Harmful™, as far as I'm concerned. Will not use on new projects. The license is weaponized & very harmful to users.
9
202
WebRTC is FINALLY supported in Safari. Coming to iOS 11 and macOS 10.11, 10.12, & 10.13!
8
189
Replying to
If these creative and brilliant folks could make a decent living writing open source software to benefits the commons instead of seeking private contracts writing proprietary code for a single company, we'd all have more innovative open source software to use. Everyone wins. 2/2
13
187
We replaced require('mod') and `module.exports` which are simple and beautiful with this over-engineered nonsense
Image
15
187
Chakra UI is the best frontend component library, hands down. If you haven't used it, you're missing: - Components are beautiful by default - Accessible HTML - Responsive maintainers - Active community - Thoughtful and delightful API design I'm a huge, huge fan
Quote
Made with Chakra UI 🤩🤩 twitter.com/feross/status/…
8
188
You wouldn't need to "code split" if you wrote less code, used smaller libraries, or simplified your app. Think before you over-engineer!
12
169
Node v0.10 will be completely UNSUPPORTED in just 50 days. No security fixes. It's time to update to Node v4, folks. Join us in the future.
4
176
It is not that uncommon for the cost of an abstraction to outweigh the benefit it delivers. Kill one today! — John Carmack
6
162