4 ms·
It's amazing that something like cssnano would have a dependency on getting MAC addresses. WTF?
by andyana 8y ago
It's amazing that something like cssnano would have a dependency on getting MAC addresses. WTF?
- zajd 8y agonpm was a mistake
- always_good 8y agoNPM doesn't change anything here. the same issue would exist if you could only vendor dependencies. Are you sure you understand the issue?
- tzahola 8y agoJavascript was a mistake Edit: Answer to “always_good”: If a toddler shoots himself with a handgun, we can say that his mistake was pulling the trigger. While technically correct, it’s not addressing the real issue, that is, how did the toddler get hold of the gun in the first place?
- always_good 8y agoWrong again. Passing user input into arbitrary shell commands is the mistake. Good examples of amateur criticism that plagues our field, though.
- supermdguy 8y agoHaving the ability to execute arbitrary commands isn't something that's unique to JavaScript.
- scrollaway 8y agoThis isn't a case of JS gun gone wrong. Someone's passing cat inside exec with an arbitrary path instead of using native open&read and path.join. That's a thing possible in almost every modern language. Stop the nonsense. Seriously. Stop.
- mrwilhelm 8y agoProgramming was a mistake.
- roblabla 8y agoI maintain a package that has an indirect dep to macaddress because of UUID generation. UUID v2 is generated from Mac address + timestamp. My package only generates uuid v4 (fully random) and even if it was, the uuid dep doesn't expose the vulnerable argument. As such it isn't vulnerable. But the dep is still there. This isn't surprising at all tbh.
- bluetech 8y agoA dependency for uuid4 is hardly needed: crypto = require('crypto'); function uuid4() { const bytes = crypto.randomBytes(16); bytes[6] = (bytes[6] & 0x0f) | 0x40; bytes[8] = (bytes[8] & 0x3f) | 0x80; return bytes.toString('hex').match(/(.{8})(.{4})(.{4})(.{4})(.{12})/).slice(1).join('-'); }
- _wmd 8y agov1 and v2 UUIDs are derived from a MAC address by specification, the uniqueness of the v1 scheme in particular depends on it. Whether that's a good idea or not is another topic entirely, but if you want to conform to spec, an implementation needs to be able to read MAC addresses
- bluetech 8y agoPlease see the comment I replied to.
- roblabla 8y agoI mean sure. But I also need to parse UUID. And do other things with it. Even if I didn't need to, I'd still likely use the uuid-1345 crate for it. Here's the thing: If I import this code in my codebase directly instead of using a library, it suddenly becomes my "responsibility" if it breaks. And when we're talking about a FOSS side-project, I don't have that kind of time. Third-party libraries means I get any improvements and bug-fixes for free. And if it breaks, I get to talk with the original maintainer to figure it out, and we're suddenly two people, with one hopefully knowledgable enough on the topic, working on the problem. Importing this kind of thing in make codebase makes it an ugly unwieldy mess that will inevitably break, and I suddenly will be alone trying to figure out what I did wrong. This is what's good about npm and libraries: the community that's built around it.