Anybody know the time-to-discovery? Any metrics on the # of impacted users?
-
-
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
That's why sometimes re-inventing the wheel is the way to go. Trust no one.
-
Bad idea for most people as they will 100% make some n00b security mistake. Most web devs don't even know what is in the libraries they import or if a dependency of a dependency has some vuln (unless they are warned by git...) npm is even worse.
-
Well, most people can't re-invent the wheel properly. Some don't even know how the current wheel that they're using works!
- End of conversation
New conversation -
-
-
sudo install internet
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Now look at this in the context of shops running many thousands of servers per admin with the same exact unaudited code as thousands of other shops doing the same. Puppet, ansible, chef, etc etc. Turns out admins in the hundreds of servers stage weren’t doing nothing.
-
Nobody was reading the source of every library and tool we used before deploying it. This is not the axe you're looking for.
-
LOL. That level of audit from one amazing person is hardly the point. Diversity of implementation. That is the point. Linux has become a monoculture. That's what made Microsoft so weak for so long. The likelihood of oversight is the same but the impact is WAY higher.
-
We don't have a monoculture. We have an explosion of unvetted software. Quite the opposite.
-
We have an explosion of uncurated repositories, indistinguishable by average users from curated ones, made way too easy to use.
-
There is that, but that's easily defined/curable. The casually curated but widely used repos scare me. The illusion of security.
-
By curation I mean something like Debian. All the language-specific library repos are uncurated in my book.
-
anything that doesn't come in the language library is uncurated, oops, JS has no standard library itself
- 1 more reply
New conversation -
-
-
This is why I don't like most of these unknown libraries. Npm and the JavaScript world is even worse.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
What’s really on our minds here: index.php? For reals?
-
just to mix things up, has pip backdoors are written in PHP, and npm backdoors in C#
End of conversation
New conversation -
-
-
creator needs to be doxxed. agreed?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
What the... trust no one.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
