3 ms·
You acknowledge security as "the real issue" in your comment. I don't know how to square that with the first sentence in your comment, "I just don't see how thi
by gary_bernhardt 8y ago
You acknowledge security as "the real issue" in your comment. I don't know how to square that with the first sentence in your comment, "I just don't see how this matters." It matters because of security, like you said.
- linkmotif 8y agoInstall a CSP and you’re done? (assuming we’re talking about front end code)
- gary_bernhardt 8y agoThat's not the kind of security problem we're talking about here. https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident https://blog.npmjs.org/post/180565383195/details-about-the-e...
- linkmotif 8y agoHuh? This is an issue affecting backend JS. We are discussing front end applications.
- gary_bernhardt 8y agoThere's nothing special about "backend". It's normal for the client side bundle to contain many dependencies that came from NPM.
- linkmotif 8y agoRight but if they can’t phone anywhere when the client executes them, they’re not dangerous to the client. As another commenter points out though, there is the danger of executing on the dev’s computer: I guess that is true.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- hombre_fatal 8y agoEven if this code is only run on the developer's machine, you're trusting 1,600 entities to not pwn it one day. It's worth some concern. As the copay attack shows, that everyone uses these libraries doesn't let us rest assured. There are virtually zero eyeballs on the code of transitive dependencies because you would have to extract tarballs to read code. And attacks can be extremely targeted. The copay attack was only discovered because of a deprecation warning in the attacker's code that someone reported.
- linkmotif 8y agoThat is true. Thank you. But is that the totality of the danger, then?
- VonGallifrey 8y agoAparently not true. https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5 https://hackernoon.com/im-harvesting-credit-card-numbers-and...
- linkmotif 8y agoVery interesting. Thanks for posting! His section about circumventing CSPs was particularly interesting and relevant. CSPs were an impediment to him, and he avoided operating his scam on sites where a CSP was installed.
- VonGallifrey 8y agoHe was also able to go around CSP. I am not a frontend developer, but I really don't like how frontend developers seem to treat security and dependencies. It really isn't normal to have 1000+ dependencies and it really isn't safe. Just saying "CSP will protect us" isn't good enough.
- linkmotif 8y agoYeah I agree except I don’t understand what the point of the tweet was. Whether you have 1000 deps or 10 deps, the problem is about security, not dep count. Who’s going to carefully audit 10 deps when they’re transitive? More than would audit 1000, but not many more. Having few deps does not appear to be the solution to dependency security.
- VonGallifrey 8y ago> Who’s going to carefully audit 10 deps when they’re transitive? I do. That is why I don't have many deps in general. Transitive or not. With only a handful of dependencies that are from trusted sources and that are audited by me I can be sure that they are safe. With 1000+ dependencies that are from as many random sources you can not do the same. Having 10 dependencies is drastically different from a security aspect then 1000+.