3 ms·
This is a bit like saying we left the safe open and nothing was stolen so its not that big of a security problem. The specifics of the exploit is besides the po
by throw2016 7y ago
This is a bit like saying we left the safe open and nothing was stolen so its not that big of a security problem. The specifics of the exploit is besides the point as it could be anything.
This is an indictment of the designers of wild lands systems like ruby Gems and npm and a culture of pulling in hundreds of dependencies that simply cannot be verified by end users.
It's one thing if this was just for developers who made a conscious decision to use a gem or npm package, but the whole system is carried on to end users who are expected to have a build environment and pull in hundreds of unknown gems and packages which in turn pull in their own dependencies simply to deploy.
This is bad engineering and design, it not only dramatically increases the complexity of deployment and wastes millions of man hours in debugging, versioning and build issues but leaves end users exposed to security issues.
- freedomben 7y agoI agree with you, but I do think the ease with which dependencies are managed in eco-systems like Ruby and JS is quite valuable. As most security-related things it's a cost/benefit analysis, and the benefit of the current systems are very high. I do wish we'd move toward more of a system of forced MFA, GPG signed binaries, and a lot more conservatism on the part of developers before pulling in other gems. I don't think it's realistic to abandon it.