4 ms·
I love this article. It's funny and informative in a consice manner. As a javascript dev with a security mindset the npm package repository and similar ones ar
by ecmascript 4y ago
I love this article. It's funny and informative in a consice manner.
As a javascript dev with a security mindset the npm package repository and similar ones are kind of scary since it's very hard if not impossible to inspect every package for every update etc.
As soon as you run any framework or basically any bigger library at all you're in the hands of hundreds if not thousands of other people. It's like something big is just around the corner to happen and it can be used to make massive damage. If I were a state actor for example, I would use npm and similar tools to be able to shut down sites and systems on a massive scale at will if a war would break out or similar.
The thing is that if you would not use any libraries and similar it would be much harder to compete against the people and companies that do use all the libraries.
So what can you do? I guess the main thing is to use a language that has a massive standard library which you don't need so many external packages. That way, every change is at least audited and perhaps it's possible to audit all the external packages you need yourself?
- mike_HGolang 4y agoonce static code analyisis gets better this will become easy to detect.
- dane-pgp 4y agoI don't know why you are being silently downvoted, as I think it is worth talking about the potential of using static analysis to improve things. One promising approach is Endo[0] which "uses LavaMoat to automatically generate reviewable policies that determine what capabilities will be distributed to third party dependencies." [0] https://github.com/endojs/endo https://github.com/endojs/endo
- rpigab 4y agoI've asked myself the same a couple years ago, auditing yourself is impossible, it could be done by a third party but it'd be expensive if they do it for your particular use case. Another possibility, still by third parties, but auditing udates to open source code for the public to use, they'd have to use certificates to sign updates, we'd need a secure version of NPM which only contains audited packages. There would exist good audits and bad ones so you'd have to choose depending on level of quality, and you'd have to pay them too somehow. And there's a solution that would be a cheap way of finding the most obvious problems: AI-augmented audit, easy to automate, but could probably be fooled by some code changes.