Introduction
Introduction Statistics Contact Development Disclaimer Help
Post AyIaieGwqLTm6dw9Z2 by [email protected]
More posts by [email protected]
Post #AyHwhVlD0azrFbzh8S by [email protected]
1 likes, 4 repeats
npm was a mistake. the concept of pulling live dependencies that are not collec…
Post #AyHxyMbKPr3FijyKzw by [email protected]
0 likes, 0 repeats
@0xabad1dea well, isn’t that mostly on the consumer? Would you feel the same…
Post #AyHxyMiPzUis4jI036 by [email protected]
0 likes, 1 repeats
@VioletBackpack “would you feel the same way if the circumstances were utterl…
Post #AyHyymYzzKfsCCe7eq by [email protected]
0 likes, 0 repeats
@0xabad1dea I wonder why maven is not constantly detonating into our faces like…
Post #AyHz02gpW5HiV4uTh2 by [email protected]
0 likes, 0 repeats
@0xabad1dea compounded by the way npm (client) does version management—not us…
Post #AyHz045KKUTSpLNYW0 by [email protected]
0 likes, 0 repeats
@0xabad1dea and the prodigious use of npx makes things even worse! It might use…
Post #AyHz1ATS3oAyvrBmYi by [email protected]
0 likes, 0 repeats
@0xabad1dea I struggle with this take because I very much succeeded at contribu…
Post #AyHzpMlocLxfXziOEi by [email protected]
0 likes, 1 repeats
@0xabad1dea It's true that taking random dependencies without thought for h…
Post #AyI0dksvEZs8oh4B28 by [email protected]
0 likes, 0 repeats
@dougwade @0xabad1dea PyPi, Pub, etc have similar issues, but it is also at the…
Post #AyI0dl0ila6vCsiPBo by [email protected]
0 likes, 0 repeats
@zeyus @0xabad1dea I think you very much understand my conflict. My needs as a …
Post #AyI0dl7oLDmXYs24Ey by [email protected]
0 likes, 1 repeats
@dougwade @zeyus I think there is a most right answer but it involves a lot of …
Post #AyI2gA8qV6DZdXn3Oy by [email protected]
0 likes, 0 repeats
@0xabad1dea This. Thank you for calling it out. Can we also kill pip please? …
Post #AyI2iIy8eTgBaqnsg4 by [email protected]
0 likes, 0 repeats
@dougwade @0xabad1deaNo offence but your words sound naive to me. Trusting tha…
Post #AyI2iJ5aCndNxwHpHU by [email protected]
0 likes, 0 repeats
@TrimTab @0xabad1dea if your only goal is to produce secure systems, I can unde…
Post #AyI2kmqKYGwCpEKot6 by [email protected]
0 likes, 0 repeats
@DJGummikuh @0xabad1dea It could be attributed to a different attack surface an…
Post #AyI2mNbXMKvd81Au4e by [email protected]
0 likes, 0 repeats
@malwareminigun apt packages are usually months or years behind what you can ge…
Post #AyI2mPdjn7sRRQDgmW by [email protected]
0 likes, 0 repeats
@E_net4 @0xabad1dea interesting point
Post #AyI2nljJ9CFCF1TK7s by [email protected]
0 likes, 0 repeats
@0xabad1dea I would have just stopped after the first sentence. 🙃But also so…
Post #AyI45if7OJFttUdTIe by [email protected]
0 likes, 0 repeats
@0xabad1dea npm is a bloody _nightmare_ if you're serious about security (P…
Post #AyI46tgNu2dyMYn0uO by [email protected]
0 likes, 0 repeats
@0xabad1dea Welcome to the Crapness, THE CRAPNESS, of ModernSoftware[TM] !
Post #AyI7NHoOG6qjh52aUC by [email protected]
0 likes, 0 repeats
@0xabad1dea CPAN, Ruby Gems, and Pypi really blazed this trail
Post #AyI7PgJ0A9H6EsV7kO by [email protected]
0 likes, 0 repeats
@0xabad1dea I still have a cpan.org email 😬
Post #AyI7PiNKT1vOesXblo by [email protected]
0 likes, 0 repeats
@mcgrew @0xabad1dea using predefined modules isn’t a bad thing in general. Of…
Post #AyI7QsNUlMq3yFAl1c by [email protected]
0 likes, 0 repeats
@0xabad1dea @malwareminigun in addition there is also a distribution adjacent m…
Post #AyIAZ34HCXpRIvlu08 by [email protected]
0 likes, 0 repeats
@0xabad1dea nobody enforces to use all packages. It's like PIP
Post #AyIBIpFOuz17lGnrM0 by [email protected]
0 likes, 1 repeats
I’m not saying “fuck hobbyists and beginners” I’m saying maybe the code…
Post #AyICJX0yIBelSPxEeW by [email protected]
0 likes, 0 repeats
@0xabad1dea Sure, but the amount of code written by hobbyists that is also part…
Post #AyICJX7LuSlDmCwKbA by [email protected]
0 likes, 1 repeats
@tribut "there's too much hobbyist code in critical infrastructure to …
Post #AyICUmI5puUu1MKFbk by [email protected]
0 likes, 0 repeats
@[email protected] how is that npm specific??
Post #AyICUmRfGK9aV2ntWi by [email protected]
0 likes, 1 repeats
@m .... who said it was???? "x was a mistake" does not imply it's…
Post #AyICkMRjh2BuV0Gaki by [email protected]
0 likes, 1 repeats
@0xabad1dea *Especially* when coupled with dependencies not being hard-bound to…
Post #AyIDuKukLOdgb69lS4 by [email protected]
0 likes, 0 repeats
sorry to everyone engaging on a reasonable basis but I have to mute this thread…
Post #AyIDuL3boRjD2aIqGW by [email protected]
0 likes, 0 repeats
@0xabad1dea pancake waffle? As in argue whether a waffle is a pancake or not?
Post #AyIDuLEb9aWDafRcOW by [email protected]
0 likes, 0 repeats
@arichtman @0xabad1dea it's the ol' "oh you like pancakes? so you …
Post #AyIDuLNScdbk29ahCy by [email protected]
0 likes, 0 repeats
@arch @arichtman in this case I'm getting a pretty funny variant:"I do…
Post #AyIDuNH9Z3kbvAegee by [email protected]
0 likes, 0 repeats
@0xabad1dea oh dang I sniped myself here. *is* a waffle a pancake variant?
Post #AyIDuTaA7IWNTrax7I by [email protected]
0 likes, 0 repeats
@arch @0xabad1dea oh okay, thank you!
Post #AyIDvCovvE4hmhqst6 by [email protected]
0 likes, 0 repeats
@0xabad1dea yeah every company I know that has thought about this for more than…
Post #AyIDvDNJrNa3VLwLU8 by [email protected]
0 likes, 0 repeats
@0xabad1dea I can count how many I've seen do a *really* thorough job of de…
Post #AyIDw0wRZZn9ETkaXI by [email protected]
0 likes, 0 repeats
@0xabad1dea @tribut the twist ending here is that the non-hobbyist code is wors…
Post #AyIDw14x3wb5erjNnU by [email protected]
0 likes, 0 repeats
@glyph @0xabad1dea @tribut I'm still waiting for the "good housekeepin…
Post #AyIDwF6WusB79oZqCW by [email protected]
0 likes, 0 repeats
@gsuberland @0xabad1dea every company I've worked for didn't even bothe…
Post #AyIDwdpiyUadqvuGye by [email protected]
0 likes, 0 repeats
@wasabi @0xabad1dea I've been doing appsec consulting stuff for 12 years no…
Post #AyIDyyq5qW2da4C7BQ by [email protected]
0 likes, 0 repeats
@0xabad1dea Open Source as a concept should be so well funded by the government…
Post #AyIE0AW7ug2W5ZQDKq by [email protected]
0 likes, 0 repeats
@0xabad1dea In most conversations I'm the one with the doom 'n gloom, b…
Post #AyIE0KjbvOldmHo7k0 by [email protected]
0 likes, 0 repeats
@DJGummikuh @0xabad1dea Maven Central has some verification steps for "own…
Post #AyIE0XAHi3EaKUNaz2 by [email protected]
0 likes, 0 repeats
@mrotteveel @DJGummikuh @0xabad1dea Signing etc. might not be harder once you g…
Post #AyIE1cYNA1JRKbAHKa by [email protected]
0 likes, 0 repeats
@0xabad1dea As a product manager who frequently sees the cleanup costs for stuf…
Post #AyIE6WSBGczVrQbcsy by [email protected]
0 likes, 0 repeats
@0xabad1dea @malwareminigun aren't security patch applied to apt package in…
Post #AyIE9wHtfmjQqvQPI0 by [email protected]
0 likes, 0 repeats
@0xabad1dea @dougwade @zeyusi diagnose the root problem as corporate open sourc…
Post #AyIEAknVsVjNVSbMVk by [email protected]
0 likes, 0 repeats
@[email protected] oh come on, you chose to single out npmnpm is the …
Post #AyIFm0di2cUJJ9LQcS by [email protected]
0 likes, 1 repeats
@davidgerard @0xabad1dea @dougwade @zeyus in conclusion, AGPL everything. or, a…
Post #AyIGTd0vF3j2mB09D6 by [email protected]
0 likes, 0 repeats
@glyph @0xabad1dea @tribut The EU is trying that, right? Does Geomys have stric…
Post #AyIGTxEQ4aPDTpTD1c by [email protected]
0 likes, 0 repeats
@0xabad1dea @arch @arichtman I mute at the first offense these days. Very satis…
Post #AyIGVKOdQs5Bc7u4FU by [email protected]
0 likes, 0 repeats
@dequbed @0xabad1dea Open Source is actually about five or six different concep…
Post #AyIGWxiIjmpHqMshQO by [email protected]
0 likes, 0 repeats
@0xabad1dea only if you expect the codebase to be of high quality. I can't …
Post #AyIGXBs26OvfkbXfXM by [email protected]
0 likes, 0 repeats
@0xabad1dea @arch @arichtman https://youtu.be/X1beEuBV7M0
Post #AyIHdbMUL6DcVBPNJ2 by [email protected]
0 likes, 0 repeats
@filippo @0xabad1dea @tribut this is my point. Nobody pays for go. So nobody wo…
Post #AyIHeCJEy8bb5pAnse by [email protected]
0 likes, 0 repeats
@0xabad1dea @dougwade @zeyus the entire discussion reminds me of the business c…
Post #AyIHefL12cFz7jE8Aq by [email protected]
0 likes, 0 repeats
@0xabad1dea sorry, I was trying to be reasonable, Im not a fan of npm and wasn�…
Post #AyIHfOXIzlpFIsK54q by [email protected]
0 likes, 0 repeats
@filippo @0xabad1dea @tribut I think questions about whether e.g. a patreon inc…
Post #AyIJzfyu2nrb6n1vTE by [email protected]
0 likes, 0 repeats
@david_chisnall Your observations are matching my experience of enterprise work…
Post #AyIK0H1KKkmrz1Rssy by [email protected]
0 likes, 0 repeats
@mainec @0xabad1dea @dougwade @zeyus do we see this happening yet? if not, why …
Post #AyIK0TrsZBxDpU81Sq by [email protected]
0 likes, 0 repeats
@muhanga The other variation I've seen of this is:Use [A]GPL'd project,…
Post #AyIK1ImJHenpiyunMe by [email protected]
0 likes, 0 repeats
@filippo @0xabad1dea @tribut give me right-wing oil-billionaire think-tank leve…
Post #AyIK1IsKvFci1fjbl2 by [email protected]
0 likes, 0 repeats
@glyph @0xabad1dea @tribut So would strict liability be mandatory, or something…
Post #AyIK1IzQUtIKNf3GoC by [email protected]
0 likes, 0 repeats
@filippo @glyph @0xabad1dea @tribut at the moment there's no liability at a…
Post #AyIK1J7a0ZogmwrmW8 by [email protected]
0 likes, 0 repeats
@filippo @glyph @0xabad1dea @tribut our understanding is that courts wouldn&#39…
Post #AyIK1JDxcqv96jqsSm by [email protected]
0 likes, 0 repeats
@filippo @glyph @0xabad1dea @tribut when software failures cause large-scale ha…
Post #AyIK405ZE8R2d4D248 by [email protected]
0 likes, 0 repeats
@filippo @glyph @0xabad1dea @tribut Under the CRA the person “placing the pro…
Post #AyILFDuCIUvecVo3ea by [email protected]
0 likes, 0 repeats
@ireneista @filippo @0xabad1dea @tribut from what I can tell the main thing tha…
Post #AyILFE0vtSJgxOxR9U by [email protected]
0 likes, 0 repeats
@glyph @filippo @0xabad1dea @tribut yes, agreed
Post #AyILHUIUK9Xq2OFQx6 by [email protected]
0 likes, 0 repeats
@ireneista @filippo @glyph @0xabad1dea @tribut well, the cyber resiliency act i…
Post #AyILHj0xbbR9gNA9DM by [email protected]
0 likes, 0 repeats
@filippo @glyph @0xabad1dea @tribut anyway, we don't claim to know what the…
Post #AyILIA4526yXZrpWKG by [email protected]
0 likes, 0 repeats
@ireneista @filippo @0xabad1dea @tribut You are correct that there need to be r…
Post #AyILIABWaQvjwxJSvg by [email protected]
0 likes, 0 repeats
@ireneista @filippo @0xabad1dea @tribut The principle that I'm advocating f…
Post #AyILIAHYE1kcFe8HK4 by [email protected]
0 likes, 0 repeats
@glyph @filippo @0xabad1dea @tribut then, we agree on that part :) (and we don&…
Post #AyILIAOdnfQEbdRwNE by [email protected]
0 likes, 0 repeats
@ireneista @filippo @0xabad1dea @tribut more generally, I think contracts of ad…
Post #AyINDXJvLGC4ADAB2O by [email protected]
0 likes, 0 repeats
@david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus there's no better…
Post #AyINHRlxuUPs7G8zLM by [email protected]
0 likes, 0 repeats
@dougwade @0xabad1dea I would blame more on people working in critical sectors …
Post #AyINJfqgXwBmLrPhrM by [email protected]
0 likes, 0 repeats
@gcb @davidgerard @zeyus @0xabad1dea @dougwade just throwing hands up and using…
Post #AyIS0R5tgAgWrMAtqS by [email protected]
0 likes, 0 repeats
@david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus in all my years, do y…
Post #AyIS31SRS1muDbxACO by [email protected]
0 likes, 0 repeats
@ireneista @glyph @filippo @0xabad1dea @tribut I literally just got $1 in *coup…
Post #AyISCsJiI6qqlTZJvE by [email protected]
0 likes, 0 repeats
@gcb @zeyus @0xabad1dea @david_chisnall @dougwade you're arguing with a Fre…
Post #AyITSg2To9P1Gybfnc by [email protected]
0 likes, 0 repeats
@david_chisnall @davidgerard @zeyus @0xabad1dea @dougwade good for you, but not…
Post #AyITTnEEYwnrrPdXCS by [email protected]
0 likes, 0 repeats
@davidgerard @gcb @zeyus @0xabad1dea @dougwade I'm also the maintainer of a…
Post #AyITWIJZxKB2qsKUYC by [email protected]
0 likes, 0 repeats
@rootwyrm @davidgerard @0xabad1dea @dougwade @zeyus That's the companies th…
Post #AyIYem1vrGmz6FwDTc by [email protected]
0 likes, 0 repeats
@gcb @davidgerard @0xabad1dea @david_chisnall @dougwade good for you, but not e…
Post #AyIYkBtN8DaSl0W7ma by [email protected]
0 likes, 0 repeats
@gcb @davidgerard @zeyus @0xabad1dea @dougwade I'm not sure what that's…
Post #AyIYrueN7XCZbCBPP6 by [email protected]
0 likes, 0 repeats
@rootwyrm@0xabad1dea @dougwade @zeyus @davidgerard @david_chisnallEvery company…
Post #AyIYrumWdDiw0Tzv72 by [email protected]
0 likes, 0 repeats
@bluGill @0xabad1dea @dougwade @zeyus @david_chisnall @rootwyrm Every company I…
Post #AyIYt0k3xO9smXMuiO by [email protected]
0 likes, 0 repeats
@david_chisnall @davidgerard @zeyus @0xabad1dea @dougwade your points focus on …
Post #AyIYvzXis5D9vq1AfI by [email protected]
0 likes, 0 repeats
@zeyus not sure what's your point, but that's great to hear. bsd/mit li…
Post #AyIYzFT67LXKBzPKV6 by [email protected]
0 likes, 0 repeats
@david_chisnall @gcb @zeyus @0xabad1dea @dougwade > complex legal structures…
Post #AyIZtEFHqntecIdoMy by [email protected]
0 likes, 1 repeats
@VioletBackpack you were not the person who got me annoyed enough to mute the t…
Post #AyIafZq6rt7HUNv2Lw by [email protected]
0 likes, 0 repeats
@gcb @zeyus @0xabad1dea @david_chisnall @dougwade "too haaard" is a f…
Post #AyIaieGwqLTm6dw9Z2 by [email protected]
0 likes, 0 repeats
@gcb but I am not a corporation, and I'm happy for people to use what I mak…
Post #AyIalJD5bnQteSOtxQ by [email protected]
0 likes, 0 repeats
@DJGummikuh @0xabad1dea Publishing to Maven Central is more complicated. (Most …
Post #AyIanD5NLlNNEhhPJg by [email protected]
0 likes, 0 repeats
@davidgerard @gcb @zeyus @0xabad1dea @dougwade you keep hammering on this, is y…
Post #AyIanNH5T4gapvFtxY by [email protected]
0 likes, 0 repeats
@davidgerard@0xabad1dea @dougwade @zeyus @david_chisnall @rootwyrmMy company cu…
Post #AyIb0NOkJtiuz52OnY by [email protected]
0 likes, 1 repeats
I mean, because it's had like 100 compromised packages in the last 100 days…
Post #AyIb7iyyT63VxCUFw8 by [email protected]
0 likes, 1 repeats
@m I also didn’t say I picked it out at random??? it’s in the news due to m…
Post #AyIcaBPSTDPqBK0ano by [email protected]
0 likes, 0 repeats
@glyph @filippo @0xabad1dea @tribut in our childhood, we witnessed several purc…
Post #AyIcaBWC4AnsWD9yIi by [email protected]
0 likes, 0 repeats
@glyph @filippo @0xabad1dea @tribut sorry - not Office, just Word. we're pr…
Post #AyIcaBbrj5LAnnoV8q by [email protected]
0 likes, 0 repeats
@glyph @filippo @0xabad1dea @tribut anyway we're all for the basic idea but…
Post #AyIcaBiFLMRd7anb5U by [email protected]
0 likes, 0 repeats
I mean, I kinda hate to say it, but I think the way out of this would be someth…
Post #AyIcaBoGyxGVQHcPTs by [email protected]
0 likes, 0 repeats
@JessTheUnstill @glyph @filippo @0xabad1dea @tribut the way out for who, is our…
Post #AyIcaBuIcY5NiyRDsG by [email protected]
0 likes, 1 repeats
For corporations who want to offload risk onto someone else because they don&#3…
Post #AyIfAXe5TUTpTjJets by [email protected]
0 likes, 0 repeats
@[email protected] @[email protected] I honestly don…
Post #AyIfCCgoMMrN40Nmwi by [email protected]
0 likes, 0 repeats
@rootwyrm @david_chisnall @davidgerard @0xabad1dea @dougwade @zeyus yeah, and t…
Post #AyIfEw0qouJ4D63g92 by [email protected]
0 likes, 0 repeats
@abucci @davidgerard @gcb @zeyus @0xabad1dea @dougwade Users, hobbyists, people…
Post #AyIfHBFt7TvU3zA9Ng by [email protected]
0 likes, 0 repeats
@zeyus people would have used what you contributed without drama on either lice…
Post #AyIhXTEuDrL8NjbBR2 by [email protected]
0 likes, 0 repeats
@dougwade @0xabad1deaFair enough, good point. Then i will categorize npm with …
Post #AyIhbhrxlqG2ujt4gi by [email protected]
0 likes, 0 repeats
@dirksteins @0xabad1dea Naturally there's nothing wrong with having depende…
Post #AyIk9Bgu7D0ervo728 by [email protected]
0 likes, 1 repeats
@0xabad1dea @briankrebs I’ve heard this before. Debian has about 20k packages…
You are viewing proxied material from pleroma.anduin.net. The copyright of proxied material belongs to its original authors. Any comments or complaints in relation to proxied material should be directed to the original authors of the content concerned. Please see the disclaimer for more details.