4 ms·
If everyone starts applying cooldowns, won't it postpone the problem? So now there is a considerable amount of users who are affected and someone from the affec
by zihotki 3mo ago
If everyone starts applying cooldowns, won't it postpone the problem? So now there is a considerable amount of users who are affected and someone from the affected group discovers the infection and reports it.
But if everyone will be delaying updates, won't be there less chances to catch it in time? I'm not fully sure if it's possible to preventively scan all NPM packages or how much compute it would require.
- oakesm9 3mo agoI think the idea is that it gives a bit of time for the companies which run automated scans of new versions to run through and detect any issues with new versions before users install them en-mass.
- roblabla 3mo agoThe goal is to give time for automated scanners ran by cybersecurity companies to flag malware before it gets installed on real users.
- MeetingsBrowser 3mo agoOnly a few of the recent supply chain attacks were discovered by users noticing weird behavior. The majority were noticed by maintainers or third party groups noticing things like releases not tied to a source tag, many rapid releases, etc. Cooldowns won’t stop everything, but it makes a malicious release significantly more likely to be noticed
- stusmall 3mo ago>If everyone starts applying cooldowns, won't it postpone the problem? There are still research firms who are actively and aggressively scanning new packages once they are pushed. For example socket.dev pulls new packages across ecosystems and performs automated analysis and runs it in a sandbox. We don't have to have them go boom in someone's production repos to find out there is a problem.
- NewJazz 3mo agoAlso as an upstream, if your "coworker" releases a strange package without discussing the changes with the broader maintenance group, you might notice after 3-48 hours, but probably not within the hour unless you happened to be online.
- tharkun__ 3mo agoAnd if every malware developer worth their salt now introduces code to "wait out" that period of time, we're back to square one. This assumes that they employ clandestine enough techniques that you have to actually install, wait and observe the behavior for longer than the cooldown period in order to detect this, because the code is "obfuscated" enough to evade static analysis of the code. It's anti-virus / anti-anti-virus 101 all over so to speak. The good thing I suppose is that it raises the bar. Your regular "virus generator" script kid (sorry: supply chain attack generator script kid) can no longer pull this off.
- woodruffw 3mo agoFundamentally, this is a cat-and-mouse game. But I suspect that "time bomb" techniques aren't economically viable for attackers, at least not with current patterns: current attackers demonstrate "smash and grab" tendencies because they know their access is limited anyways. Attempting to wait out a cooldown exposes them to additional detection risk. Of course, maybe the attacker profile changes over time. But that's the nature of the game.
- tedivm 3mo agoMost automated analysis isn't dependent on just behavior, but rather suspicious things in the code itself. You have a popular open source package with files that exist on pypi but not github then that's a big flag, or if a similar package suddenly has some base64encoded garbage that runs through an obfuscated exec call. In other words the simple fact that the project has obfuscated code is enough to flag for further attention. That said if the only issue is time, researchers will just run their automated analysis through machines with dates in the future alongside their normal tests.
- ronbenton 3mo agoEasy, then you just delay your project’s dependency updates just a little more than everyone else
- eru 3mo agoThe cooldowns should probably be randomised.
- woodruffw 3mo ago> But if everyone will be delaying updates, won't be there less chances to catch it in time? No: the security assumption behind cooldowns rests on security scanning parties, not on innocent users being victimized. Three days is a short cooldown, but it should be a good enough lead for scanning parties. > I'm not fully sure if it's possible to preventively scan all NPM packages or how much compute it would require. It’s not that much data, particularly for parties that are directly financially incentivized to be the first to report malware.
- moralestapia 3mo agoDo you have an example of those things you're alleging? All package malware related news I see are related to users being affected by it (then security firms do their analysis whatever) ...
- klausa 3mo agoAnalysis and detection are not the same.
- woodruffw 3mo agoIf you google “supply chain security company” you will find various companies of various reputations vying for attention in this space.
- moralestapia 3mo agoDidn't find any. Found a lot scammers, though. Just post one link of a "supply chain" problem that was prevented by any of these companies before it went into the wild and affected users. Simple.
- woodruffw 3mo agoI generally try not to name the companies directly, because I don’t want to give them free advertising. But you can look up e.g. the recent Shai Hulud campaign. > Just post one link of a "supply chain" problem that was prevented by any of these companies before it went into the wild and affected users. This is not the claim being made, since cooldowns are not widely adopted at the moment.
- tabwidth 3mo agoMost of the malicious ones just curl something in a postinstall script, scanners already catch that. The sneaky ones don't look malicious until they run, and three days may not help.
- drdexebtjl 3mo agoEvery single one now will be more sneaky, and we’ll be operating on a 3-day cooldown for no reason.
- brookst 3mo agoYou really think it has zero benefit whatsoever? Nothing malicious will be caught?
- drdexebtjl 3mo agoPretty much. These tools are effective now only because the malware doesn’t have to avoid being detected at all to be successful.
- pixl97 3mo agoHow exactly does that work? I don't think that HNers understand the recent supply chain attacks very well at all. I also don't think they realize the tests the SCA/package providers do to all the major packages. Almost all these attacks try to reach out to external sites to steal your data. That is exceptionally hard to hide in any meaningful way.
- drdexebtjl 3mo agodef steal_your_data(): if datetime.now() < three_days_after_attack: return reach_out_to_external_sites()
- mplewis 3mo agoOK, so it looks like you've still added suspicious code to your package.
- TZubiri 3mo agoThere was a story about two men and a tiger The men see the tiger, one scrambles to run and the other starts putting on their shoes "Why are you putting on shoes? You'll never outrun the tiger" "I don't need to, I just need to outrun you"
- brikym 3mo agoWhen you're running from a bear on a hiking trip you just have to be faster than your friend. So just set your cooldown slightly longer than everyone else's cooldowns. The cooldown will give security researchers some time to scan the packages so it's still good.
- deleted 3mo ago[deleted]
- cmckn 3mo agoI agree, it’s just the wrong approach. As a user, there’s no way to know if a package has been audited during the cooldown by some generous cybersecurity firm before you pull it in, it’s just wishful thinking. Minimizing your dependencies is a more effective strategy against supply chain attacks.
- pixl97 3mo agoHence by writing your own code with its own set of vulns to be detected.
- appplication 3mo agoWell, there’s always woodworking.
- swiftcoder 3mo agoUnless you are a big enough target, there is still potential value to this. Is your business worth enough for someone to spend a lot of money hunting bespoke vulnerabilities? If not, your main risk is being swept in a vulnerability affecting a common dependency, and eliminating the common dependencies removes that risk.
- rcxdude 3mo agoThe way to guarantee that is to pay one of those cybersecurity firms, that's basically their business. And the most effective strategy is to audit and review your dependencies and any updates to them. That probably constrains how many you can have, but just minimizing them is reducing the size of the target, not protecting it per se.
- kleyd 3mo agoIf you currently use a 7 day cooldown on a 0 day default. You can just use a 10 day cooldown on a 3 day default. But don't tell anyone...