6 ms·
Anyone done a security audit on this yet?
by wilt 7y ago
Anyone done a security audit on this yet?
- bnt 7y agoWhy?
- gigatexal 7y agoThe Chinese state perhaps including backdoors to spy on users?
- rat9988 7y agoI guess we should do the same about any open source project. I don't know a state who has proven to be reliable.
- shrimpx 7y agoAny state could spy on users but china is known to blatantly do so.
- tirpen 7y agoTo be fair, so is the US (NSA) , but people rarely suggest that packages from the US should be monitored extra closely for some reason. Of course every package used in any code that contains sensitive data should be audited along with its dependant, but I see no reason to be more afraid of this particular package than anything people happily install from npm.
- cbnotfromthere 7y agoYou're equating a democracy with a totalitarian state.
- TomMarius 7y agoThere is not as much history of state inference in companies in the USA as there is in China
- StreamBright 7y agoGiven Snowden’s book and other leaks this is rather silly to claim.
- TomMarius 7y agoSnowden was not talking about forced state inference in companies like with e.g. Huawei or Alibaba or many other, even small Chinese companies. While it happens, it certainly does not happen that much (while it's normal occurence in China) and if the companies are forced to something, it's most of the time through a court.
- StreamBright 7y agohttps://www.bbc.com/news/world-europe-32542140 https://www.bbc.com/news/world-europe-32542140 https://theintercept.com/2014/12/13/belgacom-hack-gchq-inside-story/ https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid... https://en.wikipedia.org/wiki/Operation_Socialist https://en.wikipedia.org/wiki/Operation_Socialist https://www.infoworld.com/article/2608141/snowden--the-nsa-planted-backdoors-in-cisco-products.html https://www.infoworld.com/article/2608141/snowden--the-nsa-p...
- iudqnolq 7y agoTwo main reasons: better track record in the specific domain of forced modifications for intelligence collection, and US-based projects already have the same level of risk. I would assume that for sensitive Chinese projects US software is considered risky.
- Vesuvium 7y agoThere's a good reason for that: US does not really need to put backdoors in software to spy. They have the largest tech companies under their legislation and can already force them to disclose information on users. Most companies won't argue and hand over things silently. They have international agreements with a number of countries for surveillance. This means that unless an app is completely hosted, in all parts from source code to production, in a privacy-friendly country, on servers provided by a privacy-friendly company and the app is made by a company in similar conditions, the US and EU have all they need.
- jjeaff 7y agoWhile there have been some serious breaches of trust, US companies have a track record of fighting governments openly in court to avoid sharing data with them. Chinese companies absolutely do not have this track record. Chinese companies are essentially an extension of the heavy hand of the Chinese Communist Party.
- wnscooke 7y agoThe naivity is astounding. The West's slow but sure efforts to equalize everything and everyone has also affected peoples' ability to discern actual threats. In a slightly more positive wording, the openness of the West is going to be its undoing, as its people and leaders can't conceive that other countries, other peoples, other worldviews aren't like theirs and want to overthrow them and subjugate them, and not exist in harmony because "all are equally valid".
- vertex-four 7y agoOur Government wants to subjugate us. So do a number of “friendly states”.
- codingdave 7y agoWe don't need to get into international politics to answer this question. Security audits are good ideas on any open source project you want to put into production. They are a good idea even if you wrote the code yourself, to make sure you didn't leave vulnerabilities in your code by accident. Securing an app, and preventing data breaches, is simply good practice as professional software engineers.
- thrower123 7y agoIt's a good idea, but increasingly impractical. Npm-based development is just such a fractal of dependencies; it'd take me a year to review everything that goes into a typical SPA, and by the time I was done 90% of the packages would have been updated significantly. I just hope the various cryptominers that get shoehorned in to umpteenth child dependencies fight against each other...
- iudqnolq 7y agoI'm confused. I would think more modular work is easier to review, plus modules allow deduplication. Is a module with 500,000 LoC in dependencies really that much harder to audit than a project that includes the same code internally?
- thrower123 7y agoA project that has 500kloc probably doesn't have anywhere the churn on most of that code that actively developed dependencies have. Most of that mass of first-party code is static and doesn't change much, if ever.
- asdkhadsj 7y agoI think the issue is each module tends to include far more code than just what the project needed. If everything was like the NPM meme where you install a package to check if something is true, then your LOC for that module with be quite limited. However a single dependency is often big itself, and the 50 dependencies it has are also quite big. The LOC in the dep-dep is not the same as if it was written by hand in the dep. So if you wrote your dep by hand you may use, say, 500,000 LOC - but with the tree of dependencies not being a 1:1 to what you use, you have to audit more like 2Mil LOC. Perhaps an audit could be aided by some sort of tree-shaking scenario, where all non-used code is removed, leaving you with the real 500,000 LOC that needs review.. Would be interesting. I've been having this same problem with Rust lately. Frankly, I think it's true for any package platform you use.
- DailyHN 7y agoPeople are saying that this looks like React Native fork. Since the project hasn't acknowledged the forking, they already have given good reason to be suspicious.
- StreamBright 7y agoDid you such a thing for React?
- asdkhadsj 7y agoDo you think that React Native was also a fork of something else?
- yorwba 7y agoDo you think that only forks of projects can have security issues?
- asdkhadsj 7y ago> Do you think that only forks of projects can have security issues? Huh? I'm replying to someone inquiring why someone else didn't review a fork. Aka, the GP was focused on the Fork aspect of Hippy, and the Parent asked about React, as if React was a fork. I think you misunderstood the comment chain. I was not even talking about security issues or how that affects forking. I was merely replying to another discussion about forking, and how React is viewed in that "forking light".
- mrtweetyhack 7y agoyou'd have to do a security audit on an hourly basis