6 ms·
I would agree if this were one of those `curl | sh` scenarios, but don't we consider things like `brew` to be sufficiently low-risk, akin to `apt`, `dnf`, and t
by hunter2_ 1y ago
I would agree if this were one of those `curl | sh` scenarios, but don't we consider things like `brew` to be sufficiently low-risk, akin to `apt`, `dnf`, and the like?
- tripplyons 1y agoAnyone can upload an NPM package without much review. For Homebrew, you at least have to submit a pull request.
- what 1y agoHomebrew has been compromised before. To think it’s immune is a bit naive.
- n8m8 1y agoAgreed that it's a bit funny given the context and no community-managed package manager should be 100% trusted. That said, I think rg is pretty well known to linux daily-drivers and they just wanted to share something quickly for powerusers who want to check their workspaces quickly. Probably better to just instruct n00bs to use grep than install a whole cli tool for searching Come to think of it, I wonder if a 2-phase attack could be planned by an attacker in the future: Inject malware into a package, flood guidance with instructions to install another popular tool that you also recently compromised... lol
- tripplyons 1y agoI'm not saying its immune. I'm saying that NPM doesn't have as many protections, making NPM an easier target.
- n8m8 1y agohttps://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malware https://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malwa... > Unfortunately, in the world of software there are bad actors that bundle malware with their apps. Even so, Homebrew Cask has long decided it will not be an active gatekeeper (macOS already has one) and users are expected to know about the software they are installing. This means we will not always remove casks that link to these apps, in part because there is no clear line between useful app, potentially unwanted program, and the different shades of malware—what is useful to one user may be seen as malicious by another. --- So there might be pull requests, but Brew's official stance is that they do not actively moderate casks for malware. I guess there's something built into the MacOS packaging step that help mitigate the risk, but I don't know much about it outside playing w/ app development in XCode.
- dmitrygr 1y ago> don't we consider things like `brew` to be sufficiently low-risk, Like ... npm?
- hunter2_ 1y agoI thought getting code into brew is blocked by some vetting (potentially insufficient, which could be argued for all supply chains), whereas getting code into npm involves no vetting whatsoever.
- n8m8 1y agoWent and found the link: https://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malware https://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malwa... > Unfortunately, in the world of software there are bad actors that bundle malware with their apps. Even so, Homebrew Cask has long decided it will not be an active gatekeeper (macOS already has one) and users are expected to know about the software they are installing. This means we will not always remove casks that link to these apps, in part because there is no clear line between useful app, potentially unwanted program, and the different shades of malware—what is useful to one user may be seen as malicious by another.
- fn-mote 1y agoNah… Everybody knows npm is a gaping security issue waiting to happen. Repeatedly. It’s convenient, so it’s popular. Many people also don’t vendor their own dependencies, which would slow down the spread at the price of not being instantly up to date.
- dabockster 1y ago> Many people also don’t vendor their own dependencies, which would slow down the spread at the price of not being instantly up to date. npm sold it really hard that you could rely on them and not have to vendor dependencies yourself. If I suggested that a decade ago in Seattle, I would have gotten booed out of the room.
- anthk 1y agoAPT repos for Debian, Trisquel, Ubuntu... require far more checkings and bureaucracy.
- socalgal2 1y agoI'll bet they don't. There's way to much churn for it all to be checked
- justusthane 1y agoNo, they are extremely well vetted. Have you ever heard of a supply chain attack involving Red Hat, Debian or Ubuntu repos?
- jonquest 1y agoYes, the XZ attack affected Fedora nightly and Debian testing and unstable. Yes, it got caught before it made it into a stable distribution (this time). https://www.redhat.com/en/blog/understanding-red-hats-response-xz-security-incident https://www.redhat.com/en/blog/understanding-red-hats-respon... https://lists.debian.org/debian-security-announce/2024/msg00057.html https://lists.debian.org/debian-security-announce/2024/msg00...
- const_cast 1y agoChurn? On Debian? It takes like 2 years to get up to date packages. This isn't NPM.