5 ms·
cursor dev here. reasonable assumptions, but not quite the case. the snyk packages are just the names of our bundled extensions, which we never package nor uplo
by ArVID220u 2y ago
cursor dev here. reasonable assumptions, but not quite the case. the snyk packages are just the names of our bundled extensions, which we never package nor upload to any registry. (we do it just like how VS Code does it: https://github.com/microsoft/vscode/tree/main/extensions https://github.com/microsoft/vscode/tree/main/extensions)
we did not hire snyk, but we reached out to them after seeing this and they apologized. we did not get any confirmation of what exactly they were trying to do here (but i think your explanation that someone there suspected a dependency confusion vulnerability is plausible. though it's pretty irresponsible imo to do that on public npm and actually sending up the env variables)
- syndicatedjelly 2y ago[flagged]
- benatkin 2y agoYeah, I strongly disagree with the way it's characterized here.
- TimTheTinker 2y ago> we reached out to them after seeing this and they apologized. How does this make it sound like they made Snyk apologize?
- IAmGraydon 2y ago[flagged]
- Atotalnoob 2y agoIt’s a techbro thing. Sama does it too
- deleted 2y ago[deleted]
- dovin 2y agoI like to call it informal case.
- not_a_bot_4sho 2y agoIt was a thing back in the late 90s. I still do it in casual conversations with friends, less so in professional settings. It's a gen X thing, like using "lol" to mean literal laughter
- mmaunder 2y agoIt’s a low effort flex. As in: you’re unimportant, this is unimportant, and I’m very busy, so I can’t or won’t bother to capitalize. Which is ironic because it’s more effort to not capitalize.
- wahnfrieden 2y agoit's many more keypresses, and using modifier keys is generally rsi-prone
- maxbond 2y agoWithout commenting on this subthread (I don't have an opinion), you or anyone else with this concern should look into sticky modifiers (modifiers that apply to the next key press without being held). They were a game changer for me personally as far as managing RSI, as I had a bad habit of tilting my wrist to eg type a capital T.
- wahnfrieden 2y agoI use thumb keys (Glove80) which helps but I need to give that a try too
- pizza 2y agoyes but there could be many possible reasons, for instance - it's muuch faster on mobile - you're aiming to convey litheness to potential target audiences who will know to recognize it as intentional litheness - you've gotten used to minimizing the amount of keystrokes necessary for communicating things, to the point it's second nature - you've worked a lot in the past with older nlp systems, where ignoring capitalization was a given for inputs anyhow, and just got used to treating it as syntactic cruft only strictly necessary in more formal settings ;)
- furyofantares 2y agoWhen I grew up online in the 90s, on IRC, AOL/AIM, ICQ and web forums, it was extremely common. Most of the people I know from then still do it, and I still do it with them and in many other places, although for whatever reason I don't do it here. Although it's 50/50 when on their phones now that phones auto-capitalize by default now.
- johnny22 2y agoit's been a thing at least on irc for at least 20 years. i've been used to it for a long time.
- urig 2y agoRules are put in place to be followed, for a reason. Capital letters at the start of the sentence increase readability. People who don't bother with them are being incosiderate towards their readers.
- wahnfrieden 2y agonot at all
- Piisamirotta 2y agoI have been thinking of this too. I find it super annoying to read and it looks unprofessional.
- demarq 2y agohow does this bother you, what greater meaning does it have?
- IAmGraydon 2y agoI tend to shy away from intentional illiteracy and laziness, both of which this is an example of. Not capitalizing does also affect readability. That said, I was honestly asking because I’ve seen it a few times on HN in the last couple of weeks and was curious if it’s coincidence or an actual trend.
- nomilk 2y ago> "pretty irresponsible" Wouldn't it be more like "pretty illegal"? They could have simply used body: JSON.stringify("worked"), i.e. not sent target machines’ actual environment variables, including keys.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- reubenmorais 2y agoIt's an unfortunate incentive structure. If you're doing offensive security research, there's two ways you can go about it: you can report the potential vulnerability without exploiting it, in which case you risk the company coming back to you and saying "thanks but we don't consider this a vulnerability because it's only exploited through misconfiguration and we're too smart for that". Maybe you get some token reward of $50. Or you can exploit it and say here's the PoC, this many people at your company fell for it, and this is some of the valuable data I got, including some tokens you'll have to rotate. This puts you into actual bug bounty territory. Certainly the PR side of things alone will incentivize them to pay you so you don't make too much of a noise about how Cursor leaked a bunch of credentials due to a misconfiguration that surely every good programmer knows about and defends against (like so many vulnerabilities seem so dumb in hindsight).
- 6mile 2y agoYeah, I agree the incentive structure is broken for bug bounty hunters. Until the BB platforms themselves create some rules for their customers and researchers, we are gonna continue to have the sh*t show that we do now. The reality is that bug bounty hunters are deploying a significant percentage of the total malicious NPM packages each month.
- mcherm 2y ago> The reality is that bug bounty hunters are deploying a significant percentage of the total malicious NPM packages each month. I don't actually think that is a bad thing. The TSA screening at airports would be vastly better if TSA maintained a "red team" that regularly tried smuggling guns (or water bottles or whatever) into airports. The agents would be more attentive if the number of incidents they dealt with was large enough that they could practice more often. The system could improve if it had actual feedback on how accurate and effective it was. And instead of agents overreacting or underreacting they could tune their responses to an appropriate level. The same applies to supply chain attacks. The REAL ones are rare, dangerous, and performed by experts; having a chance to practice catching them, to assess our detection rates, and to adjust our reactions is healthy.
- DigitalNoumena 2y agoIt may interest you that Guy Podjarny, one of the Snyk founders, now has an AI coding company (https://www.tessl.io/about https://www.tessl.io/about) that looks like a competitor of yours