3 ms·
That's not the kind of security problem we're talking about here. https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident https://blog.
by gary_bernhardt 8y ago
That's not the kind of security problem we're talking about here. https://blog.npmjs.org/post/180565383195/details-about-the-event-stream-incident https://blog.npmjs.org/post/180565383195/details-about-the-e...
- linkmotif 8y agoHuh? This is an issue affecting backend JS. We are discussing front end applications.
- gary_bernhardt 8y agoThere's nothing special about "backend". It's normal for the client side bundle to contain many dependencies that came from NPM.
- linkmotif 8y agoRight but if they can’t phone anywhere when the client executes them, they’re not dangerous to the client. As another commenter points out though, there is the danger of executing on the dev’s computer: I guess that is true.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- hombre_fatal 8y agoEven if this code is only run on the developer's machine, you're trusting 1,600 entities to not pwn it one day. It's worth some concern. As the copay attack shows, that everyone uses these libraries doesn't let us rest assured. There are virtually zero eyeballs on the code of transitive dependencies because you would have to extract tarballs to read code. And attacks can be extremely targeted. The copay attack was only discovered because of a deprecation warning in the attacker's code that someone reported.
- linkmotif 8y agoThat is true. Thank you. But is that the totality of the danger, then?