5 ms·
Whenever I read these kinds of posts on this website I think of Sterling Hayden in Dr. Strangelove. (The crazy SAC commander who thinks the Russians are plotti
by trgv 8y ago
Whenever I read these kinds of posts on this website I think of Sterling Hayden in Dr. Strangelove. (The crazy SAC commander who thinks the Russians are plotting to steal Americans' precious bodily fluids).
I understand that people don't trust the NSA/US government. And they shouldn't: the US government will always put its interests above yours and mine, and above those of allied countries.
At the same time, this stuff is bordering on parody. Very few of us (maybe none of us) need to worry about "the NSA MITM-ing our NPM packages". If you're that paranoid then you shouldn't be using github, NPM, or non-local dependencies. And of course you should be reviewing everything manually.
- himom 8y agoThat’s why I only drink rainwater and pure grain alcohol. Purity Of Essence.
- eanzenberg 8y agoI personally am not worried. If I was running some nuclear centrifuge in Iran/N.Korea/etc. then I'd be worried.
- passivepinetree 8y agoThis is another phrasing of the worn-out "If you have nothing to hide, you have nothing to fear" argument, and it doesn't have any place here.
- eanzenberg 8y agoSure if I am the moral equivalent of an authoritative gov't seeking nuclear arms.
- sanbor 8y agoI didn't mean that this is going to happen. I wanted to give an example of a potential threat. My idea was to show one of many problems with centralization and relying so much in GitHub and GitHub SSL certs. Maybe we can start signing our commits to increase security giving the potential threat. The same way that after the Snowden revelations we started using more and more HTTPS. We can also think of better ways of sharing/releasing open source code. Debian has a pretty neat system with keys so it's pretty safe to install software from their repos [1]. Maybe there is a better system to be develop than just grabbing whatever from GitHub[2] and running it in your machine. [1] https://en.wikipedia.org/wiki/Debian#Development_procedures https://en.wikipedia.org/wiki/Debian#Development_procedures [2] https://github.com/mklement0/n-install/blob/master/bin/n-install#L27 https://github.com/mklement0/n-install/blob/master/bin/n-ins...
- Kalium 8y agoThere's definitely a need for a better system. Some would argue that we have package managers specifically to help solve this problem. Yet, for many developers who just want a "good enough" install system without thinking or working at it much, curl-and-exec gets the job done. That so many people aren't thinking about security at all is a sad comment on the state of software engineering. But perhaps inevitable, given our cultural history of favoring freedom over security.
- morley 8y ago> I wanted to give an example of a potential threat. I really don't like this line of thinking. It's the same one used by news organizations to plump up their stories, or by politicians to make an improbable threat seem more real. In both of those cases, I think the long-term effect is to cause the public to think that very rare events are a lot more common. The result is not a culture of wariness but a culture of fear. I'd much rather people present "worst-case potential threats" instead as "likely potential threats."
- sanbor 8y agoIn security many things are "potential" threats. Just being unlikely doesn't mean that the threat doesn't exists. For example, a guy found a potential threat in rails[1], and rails developers dismissed his findings as unlikely exploitable. Then the guy go and hacked GitHub to prove that the issue was real[2][3] and that even the best rails developers were vulnerable. [1] https://github.com/rails/rails/issues/5228 https://github.com/rails/rails/issues/5228 [2] https://github.com/rails/rails/commit/b83965785db1eec019edf1fc272b1aa393e6dc57 https://github.com/rails/rails/commit/b83965785db1eec019edf1... [3] https://arstechnica.com/information-technology/2012/03/hacker-commandeers-github-to-prove-vuln-in-ruby/ https://arstechnica.com/information-technology/2012/03/hacke...
- Kalium 8y agoOK. Let's not talk about potential threats. That's the language of fear, control, and paralysis. It's the language of liars and demagogues and exaggerations. Let's talk about risks and goals. The language of opportunities. An approach of `curl | bash` takes a needless amount of risk to accomplish its goals. It can do far too many things, of which it actually needs to do a small subset. It offers a lot of opportunity for bad things to happen to seize the opportunity for the things we want. Maybe there are ways to do the same things, to get the same ends, without taking on so much risk. How do you feel about this subject?
- drspacemonkey 8y agoIt also used to be considered paranoia to think that the NSA might do all the things in the Snowden leaks, but here we are.