8 ms·
I don’t think anyone has issues with pertinent content marketing that also provides something to the community. The argument can be made that the _important_ w
by elcerebro 3y ago
I don’t think anyone has issues with pertinent content marketing that also provides something to the community.
The argument can be made that the _important_ work was already done by GitHub and Phylum. This just appears to be a derivative work without any additional value add. That is, it functions mostly as an advertisement.
Doesn’t help that they clearly don’t even have all the malware packages in their system from this campaign, three weeks after the attacks…
https://socket.dev/search?e=&q=Btc-api-node https://socket.dev/search?e=&q=Btc-api-node
- ianpenney 3y agoIn his talk, Feross mentioned that it would cost approximately 1 billion dollars to scan the entire npm ecosystem. They do it on demand for their customers IIRC. Try signing up and running their scans on it.
- elcerebro 3y agoThere’s no way that’s true. Last I checked there were 16M packages in npm, not counting versions. If we bump that up to 20M and add a multiple of 30 to account for versions, we get 60M total tar.gz files we’d need to scan. At a total cost of $1B that would put scanning a single package at $16/package? Nonsense. Even at $1 in compute time on aws that feels outlandishly high… You can’t retroactively scan the package Socket missed. It was removed from npm. Scanning on demand means you’re going to miss critical relationships across threat groups, or across disparate but related packages.
- ianpenney 3y agoRetroactive scanning, you have a point. Integrating the scan into your CI/CD would catch it. As for the numbers: see 39 mins into https://youtu.be/jWujI7Hk8O4 https://youtu.be/jWujI7Hk8O4 I used to work at npm as the SRE manager right before the acquisition and the ballpark figures make sense to me.
- elcerebro 3y agoI admittedly pulled the numbers out of thin air, and things I thought I’d seen before. Had a second to sit down, and I _way_ overestimated my counts. Per NPM there are 2,480,373 packages. According to Whitesource [1] there are an average of 12.3 versions per package. This gives us a total of 30,508,587.9 archives to scan. At a cost of $1B to scan that means each package would cost $33.959… There’s no way that’s reality. That seems like several orders of magnitude too high. 1. https://threatpost.com/malicious-npm-packages-web-apps/178137/ https://threatpost.com/malicious-npm-packages-web-apps/17813...