7 ms·
The fact that http fetches and fs reads don't prompt the user are continually the craziest part of the `npx` and `package.json`'s `postinstall`. Does anyone ha
by love2read 2y ago
The fact that http fetches and fs reads don't prompt the user are continually the craziest part of the `npx` and `package.json`'s `postinstall`.
Does anyone have a solution to wrap binary execution (or npm execution) and require explicit user authorization for network or fs calls?
- 2OEH8eoCRo0 2y agoUse Rust
- user432678 2y agoAccording to the comment below, it should be “Use Java”.
- 2OEH8eoCRo0 2y agoMy comment was made in jest
- SCdF 2y agoDefinitely stop using jest
- user432678 2y agoI bet someone already had entertained an idea to add cryptominer to Jest, nobody would notice slight increase to those tests running times on CI. Maybe it could even start funding those open source maintainers enough to finally make ES6 modules non-experimental.
- 0rzech 2y agoSee https://github.com/rust-lang/cargo/issues/13897#issue-2288844675 https://github.com/rust-lang/cargo/issues/13897#issue-228884... and https://github.com/rust-lang/cargo/issues/13897#issuecomment-2104346349 https://github.com/rust-lang/cargo/issues/13897#issuecomment... .
- BrouteMinou 2y agoThey are going to mess you up, but at least, that was memory safe. Much better.
- teknopaul 2y agoJust package node_modules subdirectories as tar files. I stopped using npm a while back and push and pull tar files instead. Naturally I get js modules from npm in the first place, but I never run code with it after initial install and testing of a library for my own use.
- simpaticoder 2y agoThis is a valid choice, but you must accept some serious trade-offs. For one thing, anyone wanting to trust you must now scrutinize all of your dependencies for modification. Anyone wanting to contribute must learn whatever ad hoc method you used to fetch and package deps, and never be sure of fully reproducing your build. The de facto compromise is to use package.json for deps, but your distributable blob is a docker image, which serializes a concrete node_modules. Something similar (and perhaps more elegant) is Java's "fat jar" approach where all dependencies are put into a single jar file (and a jar file is just a renamed zip so it's much like a tarball).
- no_wizard 2y agoMay not be a well known feature however npm can unpack tarballs as part of the install process, as that’s how they’re served from the CDN. If you vendor and tar your dependencies correctly you could functionally build a system around trust layers by inspecting hashes before allowing unpacking for instance. It’s a thought exercise certainly but there might be legs to this idea
- CBLT 2y agoI think Yarn zero install is now the default, and does the same thing you're advocating? I'm not really a JS person, but it looks like it's done reasonably competently (validating checksums etc).
- jrmann100 2y agoI believe the Deno permission system[0] does what you're asking, and more. (Deno is a JavaScript runtime co-created by Ryan Dahl, who created Node.js - see his talk "10 Things I Regret About Node.js"[1] for more of his motivations in designing it.) [0] https://docs.deno.com/runtime/fundamentals/security/ https://docs.deno.com/runtime/fundamentals/security/ [1] https://www.youtube.com/watch?v=M3BM9TB-8yA https://www.youtube.com/watch?v=M3BM9TB-8yA
- DimmieMan 2y agoYes, explicitly asking you if you want to run the install script is the first warning (which pnpm can do too) Then would halt due to file access or network permissions. Could still get you if you lazily allow all everywhere though and this is why you shouldn’t do that.
- simlevesque 2y agoYes and you can run almost every npm packages: deno run npm:@angular/cli --help
- bilalq 2y agopnpm skips all `postInstall` runs by default now. You can explicitly allow-list specific ones. If you use that, I'd highly recommend configuring it to throw an error instead of just silently skipping the postInstall though: https://github.com/karlhorky/pnpm-tricks#fail-pnpm-install-on-pnpm-v10-ignored-build-scripts https://github.com/karlhorky/pnpm-tricks#fail-pnpm-install-o...
- spiffytech 2y agoBun does the same.
- bilalq 2y agoSure, but switching from node to bun is a much more invasive change than switching from npm to pnpm. And not always possible.
- spiffytech 2y agoYes. I was more pointing out that blocking postinstall scripts is becoming a trend across multiple projects. Possibly a portent for the ecosystem as a whole. I could have communicated that more clearly.
- croshan 2y agoIt's quite easy, actually. We did this at work, recently. Bun is two things. Most commonly, it's known for its Node-competitor runtime, which is of course a very invasive change. But it can also be used purely as a package manager, with Node as your runtime: https://bun.sh/docs/cli/install https://bun.sh/docs/cli/install As a package manager, it's much more efficient, and I would recommend switching over. Haven't used pnpm, though--we came from yarn (v2, and I've used v1 in past). We still use Node for our runtime, but package install time has dropped significantly. This is especially felt when switching branches on dev machines where one package in the workspace has changed, causing yarn to retry all packages (even though yarn.lock exists), where bun only downloads the new package.
- eastbound 2y agonpm should run in Docker containers by default. At least to restrict access to the project being built. But the result of a compiler will run on the machine anyway, but once again, it should be in a Docker.
- delusional 2y agoDocker is not a security boundary.
- fc417fc802 2y agoSure it is. It isn't airtight but then what is? Even KVM escapes have been demonstrated. KVM is not a security boundary ... except that in practice it is (a quite effective one at that). Taken to the extreme you end up with something like "network connected physical machines aren't a security boundary" which is just silly.
- tbrownaw 2y ago> Taken to the extreme you end up with something like "network connected physical machines aren't a security boundary" which is just silly. 1. This is why some places with secret enough info keep things airgapped. 2. OTOH, from what I recall hearing the machines successfully targeted by Stuxnet were airgapped.
- terom 2y agoYeah, you have to move it off-planet to achieve an actual security boundary. In our threat model the upper bound on the useful lifetime of the system is limited by the light-distance time from the nearest adversary.
- fc417fc802 2y agoAh yes, the "maximally aggressive grey goo" threat model.
- 2y ago
- delusional 2y agoYou're already including arbitrary code into your application. Supposedly you're intending to run that application at some point.
- nextts 2y agoWhat is the answer to that? Learn x86 and bootstrap?
- CGamesPlay 2y agoCapability-based security within Node. The main module gets limited access to the system (restricted by the command-line, with secure defaults), all dependencies have to be explicitly provided with capabilities they need (e.g. instead of a module being able to import "fs", it receives only an open directory handle to the directory that the library consumer dictates). Deno already does the first half of this.
- squiggleblaz 2y agoI kinda wish there were programming languages, where instead of saying `import module`, you said "I must be run in a context where I have access to a function with this prototype". Effectively functions instead of modules, alongside duck-typed OO if you use OO. The problem is, as soon as it becomes remotely popular, every module is going to end up saying "I must be run in a context where I have access to all the functions version 13.2 of the filesystem module wrapped up in a structure that claims to be version 13.2 of the filesystem module and which has been signed by the private key that corresponds to the filesystem module author's public key" - even though they only need a random access file handle for use as a temporary file - because otherwise developers will be anxious about leaked implementation details preventing them from making version 1.4.16 (they'll just have to make version 2.0 - who cares? their implementation detail is my security).
- pjc50 2y agoI think the WASM/WASI environment may be closest to this. But it's an interesting idea.
- davidmurdoch 2y agoThe lavamoat npm package does something similar. It's maintained by the security team at MetaMask (crypto wallet extension and app). It's used in the extension runtime as well as wraps the build process.
- feross 2y agoWe built “safe npm”, a CLI tool transparently wraps the npm command and protects developers from malware, typosquats, install scripts, protestware, telemetry, and more. You can set a custom security policy to block or warn on file system, network, shell, or environment variable access. https://socket.dev/blog/introducing-safe-npm https://socket.dev/blog/introducing-safe-npm
- no_wizard 2y agoI will say for all the (sometimes valid) complaints about NPM and the ecosystem, I don’t hear about Go. Go encourages package authors to simply link to their git repository. It is quite literally cloning source files onto your computer without much thought
- skydhash 2y agoNo code execution during dependency fetching. And the dependency tree is very shallow for most project, making it easier to audit.
- no_wizard 2y agostill no guard rails, simply raw source code. It would be easy for anything to be hiding within. Given observed behavior I doubt most people are auditing the source either It’s ripe for an exploit
- robertlagrant 2y agoThat's a different issue, which most libraries will have - when you run their code, they may do extra things. This is talking about the same thing, but at install time as well.
- no_wizard 2y agoTwo differences: Best practice now is to not run postinstall scripts by default. Yarn and pnpm allow you to do this (and pnpm at least won’t run them by default) and I believe npm now does too, and is looking at a future where it won’t run them by default. The other difference is Go had several chances to do better, and they didn’t take any steps to do so. The maintainers of NPM (the registry and tool) I’m sure would love to make a lot of changes to the ecosystem but they can’t make some of them without breaking too much, and at the scale that NOM operates it’s going to always be playing catch up with work around a and such for previous choices so they don’t say, break hundreds of thousands of CI runs simultaneously. Go iterated on its package ecosystem several times and ultimately did very little with it. They didn’t make it vastly more secure by default in any way, they were actually going to get rid of vendoring at one point, and a whole host of other SNAFUs. Go’s packaging and distribution model while simple is extremely primitive and they have yet to really adopt anything in this area that would be beneficial for security
- deepsun 2y agoSame as Python (setup.py). It's even worse in Go, as they encourage to just link github repos at the currently latest version. Only Java, .Net and R just download files, at a declared (reproducible) version.