4 ms·
Doesn’t that just move the problem 7 days down the road? I always assumed these kinds of things just burn themselves because someone gets infected and realizes,
by justsid 5mo ago
Doesn’t that just move the problem 7 days down the road? I always assumed these kinds of things just burn themselves because someone gets infected and realizes, not that there is an army of people auditing the changes. If everyone cooldowns for 7 days, it just happens later?
- chowells 5mo agoA large portion of the time, the maintainer notices what happened a few hours later. Maybe they were asleep or off doing other things for a while, but they eventually come back. And these kinds of takeovers frequently aren't complete enough to cover their tracks. So at the very least, adding a cooldown raises the difficulty of these attacks above that threshold.
- nullhole 5mo ago> large portion of the time, the maintainer notices what happened a few hours later. So add it at the package manager level instead of the user level then?
- Barbing 5mo agoWould be bad for software/progress I guess but, got me thinking of if we had an expectation a dev would post an update checksum/hash, then follow it up a day later with the update itself... (well maybe that leads to kidnappings idk) edit - heh, sibling comment on package manager-level must be much smarter
- bot403 5mo agoI fail to see how this isn't a simple cool down with more steps. It doesn't seem to add anything to the security posture of the package/update
- Barbing 5mo agoNobody can expose themselves during the danger period Dev enforces cooldown on users, not users deciding they want to be safer. Dev has extra step of ensuring they check their accounts every ~23hr indefinitely. The simple cooldown scenario sees potentially thousands of downloads of a malicious package. The 24 hour developer delay scenario sees zero downloads during the same period.
- latexr 5mo ago> Would be bad for software/progress I guess but We all need to slow down and get some perspective. “Progress” doesn’t mean “rush everything and do it now now now”. Advancements should be slow, methodical, considered. That’s a good thing, not a weakness.
- Barbing 5mo ago:) I like it. Well, it would be tough for everybody whenever a long-awaited feature arrived but was out of touch just behind the glass. Maybe will improve our delayed gratification appreciation!
- eranation 5mo agoThese get detected almost immediately, and removed by npm within hours (axios, tanstack at least)
- Hackbraten 5mo agoBut who will detect them on day one once everyone ignores them for seven days?
- bakkoting 5mo agoThese things are usually caught by tools specifically scanning npm or by the maintainers noticing their account is compromised, not by people auditing their own installed packages.
- aoeusnth1 5mo agoAI agents
- eranation 5mo agoThere are some companies that specialize in detecting those, they do it for free (and get lots of marketing for it…)