Post AyIS0R5tgAgWrMAtqS by [email protected] | |
More posts by [email protected] | |
Post #AyHwhVlD0azrFbzh8S by [email protected] | |
1 likes, 4 repeats | |
npm was a mistake. the concept of pulling live dependencies that are not collec… | |
Post #AyHxyMbKPr3FijyKzw by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea well, isn’t that mostly on the consumer? Would you feel the same… | |
Post #AyHxyMiPzUis4jI036 by [email protected] | |
0 likes, 1 repeats | |
@VioletBackpack “would you feel the same way if the circumstances were utterl… | |
Post #AyHyymYzzKfsCCe7eq by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea I wonder why maven is not constantly detonating into our faces like… | |
Post #AyHz02gpW5HiV4uTh2 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea compounded by the way npm (client) does version management—not us… | |
Post #AyHz045KKUTSpLNYW0 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea and the prodigious use of npx makes things even worse! It might use… | |
Post #AyHz1ATS3oAyvrBmYi by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea I struggle with this take because I very much succeeded at contribu… | |
Post #AyHzpMlocLxfXziOEi by [email protected] | |
0 likes, 1 repeats | |
@0xabad1dea It's true that taking random dependencies without thought for h… | |
Post #AyI0dksvEZs8oh4B28 by [email protected] | |
0 likes, 0 repeats | |
@dougwade @0xabad1dea PyPi, Pub, etc have similar issues, but it is also at the… | |
Post #AyI0dl0ila6vCsiPBo by [email protected] | |
0 likes, 0 repeats | |
@zeyus @0xabad1dea I think you very much understand my conflict. My needs as a … | |
Post #AyI0dl7oLDmXYs24Ey by [email protected] | |
0 likes, 1 repeats | |
@dougwade @zeyus I think there is a most right answer but it involves a lot of … | |
Post #AyI2gA8qV6DZdXn3Oy by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea This. Thank you for calling it out. Can we also kill pip please? … | |
Post #AyI2iIy8eTgBaqnsg4 by [email protected] | |
0 likes, 0 repeats | |
@dougwade @0xabad1deaNo offence but your words sound naive to me. Trusting tha… | |
Post #AyI2iJ5aCndNxwHpHU by [email protected] | |
0 likes, 0 repeats | |
@TrimTab @0xabad1dea if your only goal is to produce secure systems, I can unde… | |
Post #AyI2kmqKYGwCpEKot6 by [email protected] | |
0 likes, 0 repeats | |
@DJGummikuh @0xabad1dea It could be attributed to a different attack surface an… | |
Post #AyI2mNbXMKvd81Au4e by [email protected] | |
0 likes, 0 repeats | |
@malwareminigun apt packages are usually months or years behind what you can ge… | |
Post #AyI2mPdjn7sRRQDgmW by [email protected] | |
0 likes, 0 repeats | |
@E_net4 @0xabad1dea interesting point | |
Post #AyI2nljJ9CFCF1TK7s by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea I would have just stopped after the first sentence. 🙃But also so… | |
Post #AyI45if7OJFttUdTIe by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea npm is a bloody _nightmare_ if you're serious about security (P… | |
Post #AyI46tgNu2dyMYn0uO by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea Welcome to the Crapness, THE CRAPNESS, of ModernSoftware[TM] ! | |
Post #AyI7NHoOG6qjh52aUC by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea CPAN, Ruby Gems, and Pypi really blazed this trail | |
Post #AyI7PgJ0A9H6EsV7kO by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea I still have a cpan.org email 😬 | |
Post #AyI7PiNKT1vOesXblo by [email protected] | |
0 likes, 0 repeats | |
@mcgrew @0xabad1dea using predefined modules isn’t a bad thing in general. Of… | |
Post #AyI7QsNUlMq3yFAl1c by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @malwareminigun in addition there is also a distribution adjacent m… | |
Post #AyIAZ34HCXpRIvlu08 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea nobody enforces to use all packages. It's like PIP | |
Post #AyIBIpFOuz17lGnrM0 by [email protected] | |
0 likes, 1 repeats | |
I’m not saying “fuck hobbyists and beginners” I’m saying maybe the code… | |
Post #AyICJX0yIBelSPxEeW by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea Sure, but the amount of code written by hobbyists that is also part… | |
Post #AyICJX7LuSlDmCwKbA by [email protected] | |
0 likes, 1 repeats | |
@tribut "there's too much hobbyist code in critical infrastructure to … | |
Post #AyICUmI5puUu1MKFbk by [email protected] | |
0 likes, 0 repeats | |
@[email protected] how is that npm specific?? | |
Post #AyICUmRfGK9aV2ntWi by [email protected] | |
0 likes, 1 repeats | |
@m .... who said it was???? "x was a mistake" does not imply it's… | |
Post #AyICkMRjh2BuV0Gaki by [email protected] | |
0 likes, 1 repeats | |
@0xabad1dea *Especially* when coupled with dependencies not being hard-bound to… | |
Post #AyIDuKukLOdgb69lS4 by [email protected] | |
0 likes, 0 repeats | |
sorry to everyone engaging on a reasonable basis but I have to mute this thread… | |
Post #AyIDuL3boRjD2aIqGW by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea pancake waffle? As in argue whether a waffle is a pancake or not? | |
Post #AyIDuLEb9aWDafRcOW by [email protected] | |
0 likes, 0 repeats | |
@arichtman @0xabad1dea it's the ol' "oh you like pancakes? so you … | |
Post #AyIDuLNScdbk29ahCy by [email protected] | |
0 likes, 0 repeats | |
@arch @arichtman in this case I'm getting a pretty funny variant:"I do… | |
Post #AyIDuNH9Z3kbvAegee by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea oh dang I sniped myself here. *is* a waffle a pancake variant? | |
Post #AyIDuTaA7IWNTrax7I by [email protected] | |
0 likes, 0 repeats | |
@arch @0xabad1dea oh okay, thank you! | |
Post #AyIDvCovvE4hmhqst6 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea yeah every company I know that has thought about this for more than… | |
Post #AyIDvDNJrNa3VLwLU8 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea I can count how many I've seen do a *really* thorough job of de… | |
Post #AyIDw0wRZZn9ETkaXI by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @tribut the twist ending here is that the non-hobbyist code is wors… | |
Post #AyIDw14x3wb5erjNnU by [email protected] | |
0 likes, 0 repeats | |
@glyph @0xabad1dea @tribut I'm still waiting for the "good housekeepin… | |
Post #AyIDwF6WusB79oZqCW by [email protected] | |
0 likes, 0 repeats | |
@gsuberland @0xabad1dea every company I've worked for didn't even bothe… | |
Post #AyIDwdpiyUadqvuGye by [email protected] | |
0 likes, 0 repeats | |
@wasabi @0xabad1dea I've been doing appsec consulting stuff for 12 years no… | |
Post #AyIDyyq5qW2da4C7BQ by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea Open Source as a concept should be so well funded by the government… | |
Post #AyIE0AW7ug2W5ZQDKq by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea In most conversations I'm the one with the doom 'n gloom, b… | |
Post #AyIE0KjbvOldmHo7k0 by [email protected] | |
0 likes, 0 repeats | |
@DJGummikuh @0xabad1dea Maven Central has some verification steps for "own… | |
Post #AyIE0XAHi3EaKUNaz2 by [email protected] | |
0 likes, 0 repeats | |
@mrotteveel @DJGummikuh @0xabad1dea Signing etc. might not be harder once you g… | |
Post #AyIE1cYNA1JRKbAHKa by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea As a product manager who frequently sees the cleanup costs for stuf… | |
Post #AyIE6WSBGczVrQbcsy by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @malwareminigun aren't security patch applied to apt package in… | |
Post #AyIE9wHtfmjQqvQPI0 by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @dougwade @zeyusi diagnose the root problem as corporate open sourc… | |
Post #AyIEAknVsVjNVSbMVk by [email protected] | |
0 likes, 0 repeats | |
@[email protected] oh come on, you chose to single out npmnpm is the … | |
Post #AyIFm0di2cUJJ9LQcS by [email protected] | |
0 likes, 1 repeats | |
@davidgerard @0xabad1dea @dougwade @zeyus in conclusion, AGPL everything. or, a… | |
Post #AyIGTd0vF3j2mB09D6 by [email protected] | |
0 likes, 0 repeats | |
@glyph @0xabad1dea @tribut The EU is trying that, right? Does Geomys have stric… | |
Post #AyIGTxEQ4aPDTpTD1c by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @arch @arichtman I mute at the first offense these days. Very satis… | |
Post #AyIGVKOdQs5Bc7u4FU by [email protected] | |
0 likes, 0 repeats | |
@dequbed @0xabad1dea Open Source is actually about five or six different concep… | |
Post #AyIGWxiIjmpHqMshQO by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea only if you expect the codebase to be of high quality. I can't … | |
Post #AyIGXBs26OvfkbXfXM by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @arch @arichtman https://youtu.be/X1beEuBV7M0 | |
Post #AyIHdbMUL6DcVBPNJ2 by [email protected] | |
0 likes, 0 repeats | |
@filippo @0xabad1dea @tribut this is my point. Nobody pays for go. So nobody wo… | |
Post #AyIHeCJEy8bb5pAnse by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea @dougwade @zeyus the entire discussion reminds me of the business c… | |
Post #AyIHefL12cFz7jE8Aq by [email protected] | |
0 likes, 0 repeats | |
@0xabad1dea sorry, I was trying to be reasonable, Im not a fan of npm and wasn�… | |
Post #AyIHfOXIzlpFIsK54q by [email protected] | |
0 likes, 0 repeats | |
@filippo @0xabad1dea @tribut I think questions about whether e.g. a patreon inc… | |
Post #AyIJzfyu2nrb6n1vTE by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall Your observations are matching my experience of enterprise work… | |
Post #AyIK0H1KKkmrz1Rssy by [email protected] | |
0 likes, 0 repeats | |
@mainec @0xabad1dea @dougwade @zeyus do we see this happening yet? if not, why … | |
Post #AyIK0TrsZBxDpU81Sq by [email protected] | |
0 likes, 0 repeats | |
@muhanga The other variation I've seen of this is:Use [A]GPL'd project,… | |
Post #AyIK1ImJHenpiyunMe by [email protected] | |
0 likes, 0 repeats | |
@filippo @0xabad1dea @tribut give me right-wing oil-billionaire think-tank leve… | |
Post #AyIK1IsKvFci1fjbl2 by [email protected] | |
0 likes, 0 repeats | |
@glyph @0xabad1dea @tribut So would strict liability be mandatory, or something… | |
Post #AyIK1IzQUtIKNf3GoC by [email protected] | |
0 likes, 0 repeats | |
@filippo @glyph @0xabad1dea @tribut at the moment there's no liability at a… | |
Post #AyIK1J7a0ZogmwrmW8 by [email protected] | |
0 likes, 0 repeats | |
@filippo @glyph @0xabad1dea @tribut our understanding is that courts wouldn'… | |
Post #AyIK1JDxcqv96jqsSm by [email protected] | |
0 likes, 0 repeats | |
@filippo @glyph @0xabad1dea @tribut when software failures cause large-scale ha… | |
Post #AyIK405ZE8R2d4D248 by [email protected] | |
0 likes, 0 repeats | |
@filippo @glyph @0xabad1dea @tribut Under the CRA the person “placing the pro… | |
Post #AyILFDuCIUvecVo3ea by [email protected] | |
0 likes, 0 repeats | |
@ireneista @filippo @0xabad1dea @tribut from what I can tell the main thing tha… | |
Post #AyILFE0vtSJgxOxR9U by [email protected] | |
0 likes, 0 repeats | |
@glyph @filippo @0xabad1dea @tribut yes, agreed | |
Post #AyILHUIUK9Xq2OFQx6 by [email protected] | |
0 likes, 0 repeats | |
@ireneista @filippo @glyph @0xabad1dea @tribut well, the cyber resiliency act i… | |
Post #AyILHj0xbbR9gNA9DM by [email protected] | |
0 likes, 0 repeats | |
@filippo @glyph @0xabad1dea @tribut anyway, we don't claim to know what the… | |
Post #AyILIA4526yXZrpWKG by [email protected] | |
0 likes, 0 repeats | |
@ireneista @filippo @0xabad1dea @tribut You are correct that there need to be r… | |
Post #AyILIABWaQvjwxJSvg by [email protected] | |
0 likes, 0 repeats | |
@ireneista @filippo @0xabad1dea @tribut The principle that I'm advocating f… | |
Post #AyILIAHYE1kcFe8HK4 by [email protected] | |
0 likes, 0 repeats | |
@glyph @filippo @0xabad1dea @tribut then, we agree on that part :) (and we don&… | |
Post #AyILIAOdnfQEbdRwNE by [email protected] | |
0 likes, 0 repeats | |
@ireneista @filippo @0xabad1dea @tribut more generally, I think contracts of ad… | |
Post #AyINDXJvLGC4ADAB2O by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus there's no better… | |
Post #AyINHRlxuUPs7G8zLM by [email protected] | |
0 likes, 0 repeats | |
@dougwade @0xabad1dea I would blame more on people working in critical sectors … | |
Post #AyINJfqgXwBmLrPhrM by [email protected] | |
0 likes, 0 repeats | |
@gcb @davidgerard @zeyus @0xabad1dea @dougwade just throwing hands up and using… | |
Post #AyIS0R5tgAgWrMAtqS by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus in all my years, do y… | |
Post #AyIS31SRS1muDbxACO by [email protected] | |
0 likes, 0 repeats | |
@ireneista @glyph @filippo @0xabad1dea @tribut I literally just got $1 in *coup… | |
Post #AyISCsJiI6qqlTZJvE by [email protected] | |
0 likes, 0 repeats | |
@gcb @zeyus @0xabad1dea @david_chisnall @dougwade you're arguing with a Fre… | |
Post #AyITSg2To9P1Gybfnc by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall @davidgerard @zeyus @0xabad1dea @dougwade good for you, but not… | |
Post #AyITTnEEYwnrrPdXCS by [email protected] | |
0 likes, 0 repeats | |
@davidgerard @gcb @zeyus @0xabad1dea @dougwade I'm also the maintainer of a… | |
Post #AyITWIJZxKB2qsKUYC by [email protected] | |
0 likes, 0 repeats | |
@rootwyrm @davidgerard @0xabad1dea @dougwade @zeyus That's the companies th… | |
Post #AyIYem1vrGmz6FwDTc by [email protected] | |
0 likes, 0 repeats | |
@gcb @davidgerard @0xabad1dea @david_chisnall @dougwade good for you, but not e… | |
Post #AyIYkBtN8DaSl0W7ma by [email protected] | |
0 likes, 0 repeats | |
@gcb @davidgerard @zeyus @0xabad1dea @dougwade I'm not sure what that's… | |
Post #AyIYrueN7XCZbCBPP6 by [email protected] | |
0 likes, 0 repeats | |
@rootwyrm@0xabad1dea @dougwade @zeyus @davidgerard @david_chisnallEvery company… | |
Post #AyIYrumWdDiw0Tzv72 by [email protected] | |
0 likes, 0 repeats | |
@bluGill @0xabad1dea @dougwade @zeyus @david_chisnall @rootwyrm Every company I… | |
Post #AyIYt0k3xO9smXMuiO by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall @davidgerard @zeyus @0xabad1dea @dougwade your points focus on … | |
Post #AyIYvzXis5D9vq1AfI by [email protected] | |
0 likes, 0 repeats | |
@zeyus not sure what's your point, but that's great to hear. bsd/mit li… | |
Post #AyIYzFT67LXKBzPKV6 by [email protected] | |
0 likes, 0 repeats | |
@david_chisnall @gcb @zeyus @0xabad1dea @dougwade > complex legal structures… | |
Post #AyIZtEFHqntecIdoMy by [email protected] | |
0 likes, 1 repeats | |
@VioletBackpack you were not the person who got me annoyed enough to mute the t… | |
Post #AyIafZq6rt7HUNv2Lw by [email protected] | |
0 likes, 0 repeats | |
@gcb @zeyus @0xabad1dea @david_chisnall @dougwade "too haaard" is a f… | |
Post #AyIaieGwqLTm6dw9Z2 by [email protected] | |
0 likes, 0 repeats | |
@gcb but I am not a corporation, and I'm happy for people to use what I mak… | |
Post #AyIalJD5bnQteSOtxQ by [email protected] | |
0 likes, 0 repeats | |
@DJGummikuh @0xabad1dea Publishing to Maven Central is more complicated. (Most … | |
Post #AyIanD5NLlNNEhhPJg by [email protected] | |
0 likes, 0 repeats | |
@davidgerard @gcb @zeyus @0xabad1dea @dougwade you keep hammering on this, is y… | |
Post #AyIanNH5T4gapvFtxY by [email protected] | |
0 likes, 0 repeats | |
@davidgerard@0xabad1dea @dougwade @zeyus @david_chisnall @rootwyrmMy company cu… | |
Post #AyIb0NOkJtiuz52OnY by [email protected] | |
0 likes, 1 repeats | |
I mean, because it's had like 100 compromised packages in the last 100 days… | |
Post #AyIb7iyyT63VxCUFw8 by [email protected] | |
0 likes, 1 repeats | |
@m I also didn’t say I picked it out at random??? it’s in the news due to m… | |
Post #AyIcaBPSTDPqBK0ano by [email protected] | |
0 likes, 0 repeats | |
@glyph @filippo @0xabad1dea @tribut in our childhood, we witnessed several purc… | |
Post #AyIcaBWC4AnsWD9yIi by [email protected] | |
0 likes, 0 repeats | |
@glyph @filippo @0xabad1dea @tribut sorry - not Office, just Word. we're pr… | |
Post #AyIcaBbrj5LAnnoV8q by [email protected] | |
0 likes, 0 repeats | |
@glyph @filippo @0xabad1dea @tribut anyway we're all for the basic idea but… | |
Post #AyIcaBiFLMRd7anb5U by [email protected] | |
0 likes, 0 repeats | |
I mean, I kinda hate to say it, but I think the way out of this would be someth… | |
Post #AyIcaBoGyxGVQHcPTs by [email protected] | |
0 likes, 0 repeats | |
@JessTheUnstill @glyph @filippo @0xabad1dea @tribut the way out for who, is our… | |
Post #AyIcaBuIcY5NiyRDsG by [email protected] | |
0 likes, 1 repeats | |
For corporations who want to offload risk onto someone else because they don… | |
Post #AyIfAXe5TUTpTjJets by [email protected] | |
0 likes, 0 repeats | |
@[email protected] @[email protected] I honestly don… | |
Post #AyIfCCgoMMrN40Nmwi by [email protected] | |
0 likes, 0 repeats | |
@rootwyrm @david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus yeah, and t… | |
Post #AyIfEw0qouJ4D63g92 by [email protected] | |
0 likes, 0 repeats | |
@abucci @davidgerard @gcb @zeyus @0xabad1dea @dougwade Users, hobbyists, people… | |
Post #AyIfHBFt7TvU3zA9Ng by [email protected] | |
0 likes, 0 repeats | |
@zeyus people would have used what you contributed without drama on either lice… | |
Post #AyIhXTEuDrL8NjbBR2 by [email protected] | |
0 likes, 0 repeats | |
@dougwade @0xabad1deaFair enough, good point. Then i will categorize npm with … | |
Post #AyIhbhrxlqG2ujt4gi by [email protected] | |
0 likes, 0 repeats | |
@dirksteins @0xabad1dea Naturally there's nothing wrong with having depende… | |
Post #AyIk9Bgu7D0ervo728 by [email protected] | |
0 likes, 1 repeats | |
@0xabad1dea @briankrebs I’ve heard this before. Debian has about 20k packages… |