4 ms·
That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways? Also I can r
by phiresky 11mo ago
That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways?
Also I can recommend pnpm, it has stopped executing lifecycle scripts by default so you can whitelist which ones to run.
- simpaticoder 11mo agopnpm has lots of other good attributes: it is much faster, and also keeps a central store of your dependencies, reducing disk usage and download time, similar to what java/mvn does.
- ashishb 11mo ago> That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways? I won't execute that code directly on my machine. I will always execute it inside the Docker container. Why do you want to run commands like `vite` or `eslint` directly on your machine? Why do they need access to anything outside the current directory?
- bandrami 11mo agoI get this but then in practice the only actually valuable stuff on my computer is... the code and data in my dev containers. Everything else I can download off the Internet for free at any time.
- ashishb 11mo agoNo. Most valuable data on your system for a malware author is login cookies and saved auth tokens of various services.
- hinkley 11mo agoMaybe keylogging for online services. But it is true that work and personal machines have different threat vectors.
- spicybright 11mo agoYes, but I'm willing to bet most workers don't follow strict digital life hygiene and cross contaminate all the time.
- kolme 11mo agoYou don't have any stored passwords? Any private keys in your `.ssh/`? DB credentials in some config files? And the list goes on and on.
- bandrami 11mo agoI don't store passwords (that always struck me as defeating the purpose) and my SSH keys are encrypted.
- jamesnorden 11mo agoThis kind of mentality, and "seems a bit excessive to sandbox a command that really just downloads arbitrary code", is why the JS ecosystem is so prone to credential theft. It's actually insane to read stuff like that said out loud.
- bandrami 11mo agoRight but the opposite mentality winds up putting so much of the eggs in the basket of the container that it defeats a lot of the purpose of the container.
- apsurd 11mo agoit annoys me that people fully automate things like type checkers and linting into post commit or worse entirely outsourced to CI. Because it means the hygiene is thrown over the fence in a post commit manner. AI makes this worse because they also run them "over the fence". However you run it, i want a human to hold accountability for the mainline committed code.
- throwaway290 11mo agoIt's weird that it's downvoted because this is the way
- apsurd 11mo agomaybe i'm misunderstanding the "why run anything on my machine" part. is the container on the machine? isn't that running things on your machine? is he just saying always run your code in a container?
- minitech 11mo ago> is the container on the machine? > is he just saying always run your code in a container? yes > isn't that running things on your machine? in this context where they're explicitly contrasted, it isn't running things "directly on my machine"
- ashishb 11mo ago> Also I can recommend pnpm, it has stopped executing lifecycle scripts by default so you can whitelist which ones to run. Imagine you are in a 50-person team that maintains 10 JavaScript projects, which one is easier? - Switch all projects to `pnpm`? That means switching CI, and deployment processes as well - Change the way *you* run `npm` on your machine and let your colleagues know to do the same I find the second to be a lot easier.
- afavour 11mo agoThere are a great many extra perks to switching to pnpm though. We switched on our projects a while back and haven’t looked back.
- fragmede 11mo agoAm I missing something? Don't you also need to change how CI and deployment processes call npm? If my CI server and then also my deployment scripts are calling npm the old insecure way, and running infected install scripts/whatever, haven't I just still fucked myself, just on my CI server and whatever deployment system(s) are involved? That seems bad.
- ashishb 11mo agoYour machine has more projects, data, and credentials than your CI machine, as you normally don't log into Gmail on your CI. So, just protecting your machine is great. Further, you are welcome to use this alias on your CI as well to enhance the protection.
- arghwhat 11mo agoAttacking your CI machines means to poison your artifacts you ship and systems they get deployed to, get access to all source it builds and can access (often more than you have locally) and all infrastructure it can reach. CI machines are very much high-value targets of interest.
- fragmede 11mo ago
- Kholin 11mo agoI've tried use pnpm to replace npm in my project, it really speed up when install dependencies on host machine, but much slower in the CI containers, even after config the cache volume. Which makes me come back to npm.
- deleted 11mo ago[deleted]
- worthless-trash 11mo ago> That seems a bit excessive to sandbox a command that > really just downloads arbitrary code you are going to > execute immediately afterwards anyways? I don't want to stereotype, but this logic is exactly why javascript supply chain is in the mess its in.
- tetha 11mo agoAt work, we're currently looking into firejail and bubblewrap a lot though and within the ops-team, we're looking at ways to run as much as possible, if not everything through these tools tbh. Because the counter-question could be: Why would anything but ssh or ansible need access to my ssh keys? Why would anything but firefox need access to the local firefox profiles? All of those can be mapped out with mount namespaces from the execution environment of most applications. And sure, this is a blacklist approach, and a whitelist approach would be even stronger, but the blacklist approach to secure at least the keys to the kingdom is quicker to get off the ground.
- ashishb 11mo agofirejail, bubblewrap, direct chroot, sandbox-run ... all have been mentioned in this thread. There is a gazillion list of tools that can give someone analysis paralysis. Here's my simple suggestion: all of your backend team already knows (or should) learn Docker for production deployments. So, why not rely on the same? It might not be the most efficient, but then dev machines are mostly underutilized anyway.
- johannes1234321 11mo ago> command that really just downloads arbitrary code you are going to execute immediately afterwards anyways? By default it directly runs code as part of the download. By isolation there is at least a chance to do some form of review/inspection