https://www.solipsys.co.uk/Chartter/1523831884786151424.svg %3 X_1523831884786151424 lrvick 2022-05-10 01:06:47 -------------------------------- @MylesBorins I don't think we have spoken before but I have offered to chat with your team in the past, and would love the chance to discuss any real improvements coming. I am rarely on Twitter and only logged in to reply to you. Reach out to lance@distrust.co X_1521703180920561664 bentorkington 2022-05-04 04:08:04 -------------------------------- I look forward to explaining the NPM+JS ecosystem to my grandkids "So Pop, after the buffer overruns of the 90s, the race conditions of the 00's and side-channel attacks of the 10's, then what'd you do?" We basically said "fuck it", installed ftpd and did a `chmod -R 777 /lib` X_1521703725303095298 sus_admin 2022-05-04 04:10:14 -------------------------------- @bentorkington now THAT's how you own the libs! X_1521703180920561664->X_1521703725303095298 X_1521716161905188865 Aethylred 2022-05-04 04:59:39 -------------------------------- @bentorkington Everyone wants to install everything everywhere all at once (without QA gatekeeping by your OS distribution package maintainers or your sysadmins not giving you root) Wait until you hear about the reasons for using containers. X_1521703180920561664->X_1521716161905188865 X_1523985417158430720 bentorkington 2022-05-10 11:16:52 -------------------------------- https://t.co/l4NQG5drmx X_1521703180920561664->X_1523985417158430720 X_1521723823900758016 bentorkington 2022-05-04 05:30:06 -------------------------------- @Aethylred love how we spin up a multi-user multi-tasking OS so 'root' can send someone an email then vanish into the ether X_1521716161905188865->X_1521723823900758016 X_1521736913589501954 Aethylred 2022-05-04 06:22:07 -------------------------------- @bentorkington If we wanted that we could just have used GNU Hurd X_1521723823900758016->X_1521736913589501954 X_1523774962909298690 lrvick 2022-05-09 21:20:36 -------------------------------- 1. Buy expired NPM maintainer email domains. 2. Re-create maintainer emails 3. Take over packages 4. Submit legitimate security patches that include package.json version bumps to malicious dependency you pushed 5. Enjoy world domination. X_1523787247706951680 lrvick 2022-05-09 22:09:25 -------------------------------- I just noticed "foreach" on npm is controlled by a single maintainer. I also noticed they let their domain expire, so I bought it before someone else did. I now control "foreach" on NPM, and the 36826 projects that depend on it. X_1523774962909298690->X_1523787247706951680 X_1523795763016335361 Alex_frm_Alaska 2022-05-09 22:43:15 -------------------------------- @lrvick Tfw https://t.co/3rtUSmO2GR X_1523774962909298690->X_1523795763016335361 X_1523835260722499590 sickcodes 2022-05-10 01:20:12 -------------------------------- @lrvick Won't fix X_1523774962909298690->X_1523835260722499590 X_1523836882177560578 stereotype32 2022-05-10 01:26:38 -------------------------------- This was already known by NPM team afaik.... and I think there was a blog post about how they control this.. https://t.co/jk5KZJPe4f X_1523774962909298690->X_1523836882177560578 quoted by X_1523862511627509763 djchateau 2022-05-10 03:08:29 -------------------------------- God, I hate npm. https://t.co/FARIDgZJ4i X_1523774962909298690->X_1523862511627509763 quoted by X_1523948598769205248 mitt_nya_nym 2022-05-10 08:50:34 -------------------------------- define "wickedly evil".... https://t.co/SdHaxJDsme X_1523774962909298690->X_1523948598769205248 quoted by X_1523951886877011970 bagder 2022-05-10 09:03:38 -------------------------------- Explain a software supply chain problem in a tweet. https://t.co/v0M6F5iA59 X_1523774962909298690->X_1523951886877011970 quoted by X_1523953976261160960 AdamChainz 2022-05-10 09:11:56 -------------------------------- https://t.co/dUPvESliXF X_1523774962909298690->X_1523953976261160960 quoted by X_1523955111558631424 kehlarn 2022-05-10 09:16:26 -------------------------------- they said ttls were a bad thing yet... https://t.co/T0fKKyql5t X_1523774962909298690->X_1523955111558631424 quoted by X_1523962175580168194 pibbs_io 2022-05-10 09:44:31 -------------------------------- @lrvick https://t.co/NYMGsDdgdz X_1523774962909298690->X_1523962175580168194 X_1523965439403073537 yvg 2022-05-10 09:57:29 -------------------------------- One more reason to use `yarn add -E` and use static versions to prevent at the least the simplest forms of OSS takeovers from getting into your codebase. https://t.co/4P0zqy9qeK X_1523774962909298690->X_1523965439403073537 quoted by X_1523972689538469889 GabrielMagno 2022-05-10 10:26:17 -------------------------------- https://t.co/RULW6T1lzT X_1523774962909298690->X_1523972689538469889 quoted by X_1523977844170366977 eevee 2022-05-10 10:46:46 -------------------------------- This is how i got the 'eevee' username on livejournal https://t.co/7O4nUofvj8 X_1523774962909298690->X_1523977844170366977 quoted by X_1523982093403017216 grhmc 2022-05-10 11:03:39 -------------------------------- Pro tip: you can buy a domain and return it within 5 days for free. 5 days is plenty of time to get an email! https://t.co/Q2kwuIP5bo https://t.co/VX103caoiJ X_1523774962909298690->X_1523982093403017216 quoted by X_1523983004695248903 mrhands31 2022-05-10 11:07:17 -------------------------------- This is why I reduce dependencies as much as possible for my game and added node_modules to my repository directly. https://t.co/4eqO5qpmmX X_1523774962909298690->X_1523983004695248903 quoted by X_1523774962909298690->X_1523985417158430720 quoted by X_1523989433393029128 joernchen 2022-05-10 11:32:49 -------------------------------- No shit [?] https://t.co/bcfXHtRna2 X_1523774962909298690->X_1523989433393029128 quoted by X_1523989804429500418 MattRixman 2022-05-10 11:34:18 -------------------------------- @lrvick From the people who brought you blindly executing whatever code the server gives you just to figure out what this page links to... X_1523774962909298690->X_1523989804429500418 X_1523990056968638466 RichFelker 2022-05-10 11:35:18 -------------------------------- This could be fixed with some basic pubkey auth where you lose access to your package name if you lose your key and only get it back, if at all, through re-establishing trust to community. https://t.co/v2Y3qffpUt X_1523774962909298690->X_1523990056968638466 quoted by X_1523992250119864321 Gottox 2022-05-10 11:44:01 -------------------------------- It seems like everyone is bashing on NPM... Ehm, this is true for any online service that allows resetting the PW via E-Mail. Including @github. https://t.co/TSrJrlprTO X_1523774962909298690->X_1523992250119864321 quoted by X_1523992715444334592 lscoppio 2022-05-10 11:45:52 -------------------------------- @lrvick @fasterthanlime It has already happened a couple of times, ppl kindavtried to do that to mine monero, they have no creativity [?] X_1523774962909298690->X_1523992715444334592 X_1523997201709555715 sbom_x 2022-05-10 12:03:42 -------------------------------- we're already working on solutions to quickly identify those issues https://t.co/0spDW58F9T X_1523774962909298690->X_1523997201709555715 quoted by X_1523998193838657537 AntonMinashkin 2022-05-10 12:07:38 -------------------------------- Some technologies are just cursed https://t.co/d334t5Etbu X_1523774962909298690->X_1523998193838657537 quoted by X_1523998858732310529 NetGlitch 2022-05-10 12:10:17 -------------------------------- @lrvick JS ecosystem - broken AF and it's not gonna change. X_1523774962909298690->X_1523998858732310529 X_1523998944883261445 0xtosh 2022-05-10 12:10:37 -------------------------------- For all the benefits we have received from massive FOSS adaption, this is still the supply chain circus that we have lost control over and the vultures are circling. I hope it won't take a massive coordinated cyber attack to get anyone moving in this area https://t.co/AiOnNewWBi X_1523774962909298690->X_1523998944883261445 quoted by X_1524006261183889409 GNUwf 2022-05-10 12:39:41 -------------------------------- Have a CI/CD stack. Deploy a change into production. The compromised code gets pulled into the new build with zero audit, and poof, you've been p0wned. https://t.co/jOcZDsBZO9 X_1523774962909298690->X_1524006261183889409 quoted by X_1524013653623816193 m_oppitz 2022-05-10 13:09:04 -------------------------------- @lrvick Luckily, supplying that legitimate security patches is probably so much work that the maintainer email will expire again at a point, without any changes done. X_1523774962909298690->X_1524013653623816193 X_1524028585253777413 DiegoRBaquero 2022-05-10 14:08:24 -------------------------------- @lrvick @SocketSecurity @feross how is this observed/handled by Socket? X_1523774962909298690->X_1524028585253777413 X_1524020290812010497 notherealways 2022-05-10 13:35:26 -------------------------------- @lrvick Interesting ! X_1523774962909298690->X_1524020290812010497 X_1524024134644162560 iprashanth_ 2022-05-10 13:50:43 -------------------------------- https://t.co/RNCMnlR5JU X_1523774962909298690->X_1524024134644162560 quoted by X_1524020618617884673 ov3rflow1 2022-05-10 13:36:45 -------------------------------- Las cosas tambien expiran en internet. Te olvidas de renovar, y seguramente algo se ira al carajo[?]. https://t.co/uNofQwxD3A X_1523774962909298690->X_1524020618617884673 quoted by X_1524020528373108736 GabriellaG439 2022-05-10 13:36:23 -------------------------------- A lot of languages are going to be re-inventing @dhall_lang's semantic integrity checks in the near future https://t.co/f6DLg9vzFN https://t.co/gy6ShiIq5A X_1523774962909298690->X_1524020528373108736 quoted by X_1523793759112089600 gavsteed 2022-05-09 22:35:17 -------------------------------- https://t.co/xVnIxmSrm3 X_1523787247706951680->X_1523793759112089600 quoted by X_1523795057383702528 j_w_holland 2022-05-09 22:40:27 -------------------------------- And we wonder why we have a supply chain problem when the spine is this breakable. Surely it should be mandatory for checker/maker as minimum maintainers? https://t.co/jwtGmwH32K X_1523787247706951680->X_1523795057383702528 quoted by X_1523798153983537152 mikiemeatsweats 2022-05-09 22:52:45 -------------------------------- @lrvick @heavilyarmedc Why not just use the native JavaScript foreach rather than importing it from npm? X_1523787247706951680->X_1523798153983537152 X_1523804007524814848 JavaJulius 2022-05-09 23:16:00 -------------------------------- @lrvick @lorenc_dan Do you have ability to publish new versions to npmjs registry? X_1523787247706951680->X_1523804007524814848 X_1523811989797093376 MylesBorins 2022-05-09 23:47:44 -------------------------------- @lrvick Myles from GitHub/npm here The email address for an account doesn't always match the email address used to publish a package. In future if you think you've found ways to compromise high-impact accounts please feel free to submit to our bug bounty program https://t.co/CMhHw7rmH8 X_1523787247706951680->X_1523811989797093376 X_1523821115482656768 vmbrasseur 2022-05-10 00:23:59 -------------------------------- https://t.co/IZ7LbBsP0H https://t.co/IQojso5tcQ X_1523787247706951680->X_1523821115482656768 quoted by X_1523823706375524355 khenidak 2022-05-10 00:34:17 -------------------------------- This is just too broken to use for something as widely used https://t.co/WsxUmcA4sx X_1523787247706951680->X_1523823706375524355 quoted by X_1523842072222052352 deathbypapercut 2022-05-10 01:47:16 -------------------------------- Like there weren't enough reasons to be sleepless https://t.co/o0deSKczP5 X_1523787247706951680->X_1523842072222052352 quoted by X_1523930777096015874 edent 2022-05-10 07:39:45 -------------------------------- One for #CyberUK - how are you auditing your supply chains? https://t.co/n1WRbe2xbL X_1523787247706951680->X_1523930777096015874 quoted by X_1523931240566513665 jonodrew 2022-05-10 07:41:35 -------------------------------- Oh cool https://t.co/Kfyf7KVJtl X_1523787247706951680->X_1523931240566513665 quoted by X_1523939564074803200 bortzmeyer 2022-05-10 08:14:40 -------------------------------- Deux histoires de nom de domaine ce matin. Commencons par la premiere : qui controle un nom controle les adresses de courrier et par la suite controle plein de comptes. Par exemple #npm https://t.co/TxUsJmm33x #DNS #securite X_1523787247706951680->X_1523939564074803200 quoted by X_1523953541848702976 mboehme_ 2022-05-10 09:10:12 -------------------------------- Supply chain insecurity. https://t.co/zA1cSpIRfI X_1523787247706951680->X_1523953541848702976 quoted by X_1523955386230968320 slpnix 2022-05-10 09:17:32 -------------------------------- https://t.co/q76MXQfJH6 X_1523787247706951680->X_1523955386230968320 quoted by X_1523959401761193984 fluepke 2022-05-10 09:33:29 -------------------------------- A "foreach" package? Seriously?? Are the webshits okay? https://t.co/tsY4LS65Iy X_1523787247706951680->X_1523959401761193984 quoted by X_1523971149570445312 k4v 2022-05-10 10:20:10 -------------------------------- JavaScript https://t.co/I7BASxL0I4 X_1523787247706951680->X_1523971149570445312 quoted by X_1523971998912819202 agowa338 2022-05-10 10:23:33 -------------------------------- @lrvick wasn't there some guy that paid for such projects to vanish without any notice? The amount he paid was dependent on how many things break when it vanishes and also how little code the project had. A oneliner depended on by millions of projects would be the highest-paid... X_1523787247706951680->X_1523971998912819202 X_1523972785130950656 gjherbiet 2022-05-10 10:26:40 -------------------------------- As we are talking about #DNS security at the @nisduc conference, this a terrific example of the importance of good practices in domain name management... https://t.co/q2jt6TcgQt X_1523787247706951680->X_1523972785130950656 quoted by X_1523982134410715137 mueller_andi 2022-05-10 11:03:49 -------------------------------- @lrvick @Ekynos https://t.co/KIhLfqsfa9 X_1523787247706951680->X_1523982134410715137 X_1523983614786031617 HackPatch 2022-05-10 11:09:42 -------------------------------- https://t.co/wROlLU78nf X_1523787247706951680->X_1523983614786031617 quoted by X_1523983944626192384 campuscodi 2022-05-10 11:11:01 -------------------------------- More on this topic in my article from February: https://t.co/jaR33SN1eH https://t.co/M11Fnx1e5O X_1523787247706951680->X_1523983944626192384 quoted by X_1523990579205529600 emil_no 2022-05-10 11:37:23 -------------------------------- Just NPM things -\_(tsu)_/- https://t.co/VfHU10jspj X_1523787247706951680->X_1523990579205529600 quoted by X_1523991617476210689 grisu48 2022-05-10 11:41:30 -------------------------------- Your monthly dose of catastrophic supply chain issues in npm. https://t.co/ZWrBJRJ1Ql X_1523787247706951680->X_1523991617476210689 quoted by X_1523992435457544192 thedarktangent 2022-05-10 11:44:45 -------------------------------- https://t.co/lOIlvLeqyv X_1523787247706951680->X_1523992435457544192 quoted by X_1523992619927445504 domchell 2022-05-10 11:45:29 -------------------------------- https://t.co/v4V3PCL7mV https://t.co/42GSNobjQl X_1523787247706951680->X_1523992619927445504 quoted by X_1523996928526241794 o0RbR0o 2022-05-10 12:02:36 -------------------------------- @lrvick oof... X_1523787247706951680->X_1523996928526241794 X_1523997022008840195 rcklss_abndn 2022-05-10 12:02:59 -------------------------------- The JavaScript ecosystem is profoundly dysfunctional. https://t.co/TVtswMuzWB X_1523787247706951680->X_1523997022008840195 quoted by X_1524000461665325062 madplatt 2022-05-10 12:16:39 -------------------------------- If this industry is going to do something about this "supply chain security" thing, maybe we should start by looking at the incentives * this is certainly hard stuff h/t @Di4naO https://t.co/uQNSJmXf68 X_1523787247706951680->X_1524000461665325062 quoted by X_1524001993307566080 miss_inputs 2022-05-10 12:22:44 -------------------------------- Hey this might be a hot take but I don't think npm should be allowed to be a thing that programmers use https://t.co/mqNdC7cCnt X_1523787247706951680->X_1524001993307566080 quoted by X_1524004327723053063 GNUwf 2022-05-10 12:32:01 -------------------------------- This is why I have large reservations on dynamically depending on code direct from source. https://t.co/Yub0a1R9Ib X_1523787247706951680->X_1524004327723053063 quoted by X_1524004567616212992 jschauma 2022-05-10 12:32:58 -------------------------------- npm, as usual. (Plus a free "it's always the DNS", but that's a given.) https://t.co/HiGJTbxVVP X_1523787247706951680->X_1524004567616212992 quoted by X_1524011074546241538 tarah 2022-05-10 12:58:49 -------------------------------- https://t.co/qYyP1RGAFV https://t.co/HIrMJsz3h9 https://t.co/a2k7Dpiw23 X_1523787247706951680->X_1524011074546241538 quoted by X_1524012258598264833 lolowhat 2022-05-10 13:03:31 -------------------------------- https://t.co/l0hmmKOkKV https://t.co/F7tOi3hByK X_1523787247706951680->X_1524012258598264833 quoted by X_1524013071915749376 thepanta82 2022-05-10 13:06:45 -------------------------------- @lrvick Way to bury the lede. X_1523787247706951680->X_1524013071915749376 X_1523990183645007873 ChristianKuehn 2022-05-10 11:35:48 -------------------------------- Holy fuck this is evil. Creating a "harmless" npm app and offering it around, then add malware dependencies. https://t.co/ZfUM8MYtDL X_1523795763016335361->X_1523990183645007873 quoted by X_1523952489007128576 Slartibartfeast 2022-05-10 09:06:01 -------------------------------- @mikiemeatsweats @lrvick @heavilyarmedc #JustUseJquery X_1523798153983537152->X_1523952489007128576 X_1523965958242680832 tluzat 2022-05-10 09:59:33 -------------------------------- @mikiemeatsweats @lrvick @heavilyarmedc 1) There was no forEach in all common browsers when this was created. 2) It's working on objects, too. 3) It seems to originate from Underscore's each and might have been preferable to import instead of the whole library back then. X_1523798153983537152->X_1523965958242680832 X_1524026103953829889 cesarfdal 2022-05-10 13:58:32 -------------------------------- @mikiemeatsweats @lrvick @heavilyarmedc NPM should at least log some kind of warning if a package has not been updated for too long, more so if it has < 100 lines and so many others depend on it. X_1523798153983537152->X_1524026103953829889 X_1523812976813387776 MylesBorins 2022-05-09 23:51:39 -------------------------------- @lrvick This particular attack was published about in Dec 2021, and we've been aware for quite a bit longer. We have a couple of things in place to protect against it, but if you do manage to find a way to do a takeover we are keen to know! https://t.co/4cZCDODcjw X_1523811989797093376->X_1523812976813387776 X_1524002666510417921 voltagex 2022-05-10 12:25:24 -------------------------------- @joelpmichael https://t.co/TOXK8ucVKW X_1523811989797093376->X_1524002666510417921 quoted by X_1523827220023853057 lrvick 2022-05-10 00:48:15 -------------------------------- @MylesBorins I don't keep doing these stunts for bug bounties. I do them to educate the public on the risks. Account takeovers are always going to be a huge risk until NPM implements user code signing and phishing-resistant 2FA like FIDO the security research community has been begging for. X_1523812976813387776->X_1523827220023853057 X_1523837089912999937 stereotype32 2022-05-10 01:27:28 -------------------------------- https://t.co/rt9TBFvt1t X_1523812976813387776->X_1523837089912999937 quoted by X_1523982552679206912 mueller_andi 2022-05-10 11:05:29 -------------------------------- @MylesBorins @lrvick Great virtue signalling here, but that's just what he did. Also, do you really advise non-disclosure for entering into your bug bounty program? X_1523812976813387776->X_1523982552679206912 X_1524001754723069952 o0RbR0o 2022-05-10 12:21:47 -------------------------------- @MylesBorins @lrvick If you are aware about the (quite "standard") way of repository takeover for that long time, why don't you just implement few of the most basic hardening methods against it and talk about unspecific measurements against it while passive-aggressively turning against the messenger? X_1523812976813387776->X_1524001754723069952 X_1523827875685806081 lrvick 2022-05-10 00:50:51 -------------------------------- @MylesBorins To be clear, I won't -actually- login to an account I do not own, unless you are giving me permission to try. In this case all I did was send a password reset email and bailed. X_1523827220023853057->X_1523827875685806081 X_1523829510889783299 lrvick 2022-05-10 00:57:21 -------------------------------- @MylesBorins The reality is TOTP and the option to add alternative email addresses are not enough. Email accounts can be taken over, and TOTP can be phished. The solution is user code signing and we have been asking for that at least as far back as this 2013 PR: https://t.co/gIfuRydRyz X_1523827875685806081->X_1523829510889783299 X_1523830193416192000 lrvick 2022-05-10 01:00:04 -------------------------------- @MylesBorins Also after years of frustration with serious and totally avoidable NPM supply chain attack instances causing serious harm, I sent an open letter to your team covering some of this in 2020 here: https://t.co/VeCjh314xV I regret my tone, but I don't regret the calls to action. X_1523829510889783299->X_1523830193416192000 X_1523830905168670720 MylesBorins 2022-05-10 01:02:53 -------------------------------- @lrvick I'm afk for the night for family time, but will get back to you tomorrow. We have a roadmap entirely focused on security improvements and would enjoy the opportunity to chat about it. Maybe we can find time for a synchronous call in the future. X_1523830193416192000->X_1523830905168670720 X_1523831113768218627 lrvick 2022-05-10 01:03:43 -------------------------------- @MylesBorins I work with many major fintech companies to solve account takeover issues and my services remain available to the NPM team, for free if needed, if we can make some forward progress on these issues. I don't know what to do but publicly warn people not to trust NPM at this point. X_1523830193416192000->X_1523831113768218627 X_1523830905168670720->X_1523831884786151424 X_1523836882177560578->X_1523837089912999937 X_1523858898822008832 sudhanshur705 2022-05-10 02:54:08 -------------------------------- @stereotype32 IAmMandatory already did the same exact thing few months back: https://t.co/8ODYoHAQcX X_1523836882177560578->X_1523858898822008832 X_1523946972331266048 Faewik 2022-05-10 08:44:06 -------------------------------- @edent Wow, nice example of #carpetbagging A quiet "consultancy" fee of $36,826 plus costs to sell the domain back would actually be reasonable X_1523930777096015874->X_1523946972331266048 X_1523940120952516609 bortzmeyer 2022-05-10 08:16:52 -------------------------------- Et la deuxieme : quand votre BE (Bureau d'Enregistrement) ou le registre vous disent de verifier vos donnees de contact et de les maintenir a jour, FAITES-LE ! Autrement, vous risque de ne pas etre prevenu en cas de probleme et, dans le pire des cas, de perdre votre nom. X_1523939564074803200->X_1523940120952516609 X_1523943356149161984 renard_alpin 2022-05-10 08:29:44 -------------------------------- @bortzmeyer 36826 projets utilisant le paquet "foreach" alors qu'il existe : Array.prototype.forEach() https://t.co/rckpeTuWKT() Object.entries() for (const ... of ...) { } en standard dans le langage. Il faudrait que les developpeurs arretent d'ecrire et de laisser vivre du code desuet. X_1523939564074803200->X_1523943356149161984 X_1523940410015506432 bortzmeyer 2022-05-10 08:18:01 -------------------------------- C'est fou, le nombre de domaines avec des donnees de contact qui ne sont plus correctes. Dans beaucoup d'organisations, la mise a jour de ces donnees (par exemple en cas de depart) est... negligee. X_1523940120952516609->X_1523940410015506432 X_1523944042626748416 mageekguy 2022-05-10 08:32:27 -------------------------------- @bortzmeyer Autre conseil aux entreprises : n'utilisez pas une adresse de contact qui correspond a une personne physique : en cas de depart, d'absence prolongee ou de deces, ca peut devenir tres complique, utilisez plutot une adresse dediee ! X_1523940410015506432->X_1523944042626748416 X_1523956145504899077 Gwalix_tech 2022-05-10 09:20:33 -------------------------------- @bortzmeyer OVH ne facilite pas les choses, les manips pour mettre a jour ces donnees de contact chez eux sont ridicules. Aucun des formulaires ne fonctionne bien, et leur support est incompetent : pour mettre a jour ces donnees, ils me demandent de creer un nouveau compte client par domaine X_1523940410015506432->X_1523956145504899077 X_1523954647265910784 Snip6974 2022-05-10 09:14:36 -------------------------------- @renard_alpin @bortzmeyer This [?] X_1523943356149161984->X_1523954647265910784 X_1523949073262338050 R1Rail 2022-05-10 08:52:27 -------------------------------- @mageekguy @bortzmeyer et verifiez qu'il n'y ait pas de typo dans l'adresse... Une lettre qui saute c'est un mail qui n'arrive pas X_1523944042626748416->X_1523949073262338050 X_1523952364176252930 KrisBuytaert 2022-05-10 09:05:31 -------------------------------- Everthing is a fscking dns problem :) https://t.co/ubgsmDs0Ou X_1523951886877011970->X_1523952364176252930 quoted by X_1523960243272642560 beeradmoore 2022-05-10 09:36:50 -------------------------------- @bagder Works (unless it has changed) for Twitter handles too Forgot password screen would give you obfuscated email but with the full domain in tact. X_1523951886877011970->X_1523960243272642560 X_1524021090217041925 grave367 2022-05-10 13:38:37 -------------------------------- @bagder you've gotta admit, taking over the world sounds way cooler when a physical doomsday device is involved. now it's just a matter of building a bot to buy a domain and waiting. X_1523951886877011970->X_1524021090217041925 X_1523955572256960512 anthony_ricaud 2022-05-10 09:18:16 -------------------------------- @AdamChainz On the bright side, GitHub/npm are moving in the right direction: - https://t.co/dm80XIbjkV - https://t.co/HR3Rv0hpkk X_1523953976261160960->X_1523955572256960512 X_1524018063393402881 sovereignchris 2022-05-10 13:26:35 -------------------------------- @AdamChainz Is it a standard practice for a python dev to use black format. X_1523953976261160960->X_1524018063393402881 X_1524002951496409089 AdamChainz 2022-05-10 12:26:32 -------------------------------- @anthony_ricaud Indeed! But it will take a long while to permeate... X_1523955572256960512->X_1524002951496409089 X_1523961147719917568 ratlos8 2022-05-10 09:40:26 -------------------------------- @fluepke From the same motion picture company that brought you "is-equal" and its sequel "is-odd". X_1523959401761193984->X_1523961147719917568 X_1523961739733356544 zeri42 2022-05-10 09:42:47 -------------------------------- @fluepke Considering the sheer amount of insanity and or desperation the has to be required to operate that tower of bable of a technology stack I assume that's a rethorical question. X_1523959401761193984->X_1523961739733356544 X_1523961941374509058 0xdeef 2022-05-10 09:43:35 -------------------------------- @fluepke Time to find out if the customers of "foreach" rely on a stable execution order X_1523959401761193984->X_1523961941374509058 X_1523963671650656256 confuzd_ 2022-05-10 09:50:27 -------------------------------- @fluepke The package was created 8 years ago, Array.prototype.forEach is way older. There is really no need to have such a package. X_1523959401761193984->X_1523963671650656256 X_1523963793851756545 _michaelknoch 2022-05-10 09:50:56 -------------------------------- @fluepke I guess this was about browser compatibility. No need to rant about every web developer because of an unnecessary package which was updated last 8 years ago. X_1523959401761193984->X_1523963793851756545 X_1523967272846602241 dirsigler 2022-05-10 10:04:46 -------------------------------- @fluepke Weil Entwickler scheinbar sobald sie NPM anfassen alle logischen Gedanken mit dem morgendlichen Kaffee Dunschiss wegspulen. X_1523959401761193984->X_1523967272846602241 X_1523970501139386370 0xhagen 2022-05-10 10:17:36 -------------------------------- @fluepke LeftPad++ X_1523959401761193984->X_1523970501139386370 X_1523971632670609409 agowa338 2022-05-10 10:22:05 -------------------------------- @fluepke the lack of a propper standards library is getting more and more obvious. X_1523959401761193984->X_1523971632670609409 X_1523979196753657859 NetGlitch 2022-05-10 10:52:09 -------------------------------- @fluepke Nope, the webshits are not ok of course. JS ecosystem is a terrible clusterf* and apparently there will never be a motion to fix this. That community seems not to care about the things which make most others run away screaming. X_1523959401761193984->X_1523979196753657859 X_1524003350458609665 lbenedix 2022-05-10 12:28:08 -------------------------------- @fluepke no. seriously: no! https://t.co/qg4XuRoleP https://t.co/r6LOaXdG4K X_1523959401761193984->X_1524003350458609665 X_1523961436858372098 bagder 2022-05-10 09:41:35 -------------------------------- @beeradmoore ... unless you have 2fa activated. X_1523960243272642560->X_1523961436858372098 X_1524013498845609985 tc_nj7 2022-05-10 13:08:27 -------------------------------- @beeradmoore @bagder It no longer shows you the full domain - just did that for an old account this morning and took me 10 minutes to figure out what email I used!! X_1523960243272642560->X_1524013498845609985 X_1523963255466729472 0xdeef 2022-05-10 09:48:48 -------------------------------- @ratlos8 @fluepke This Christmas will be upside-down. After the 3 smash hits, their newest creation "not" is coming to cinemas near you! X_1523961147719917568->X_1523963255466729472 X_1523964428102041602 beeradmoore 2022-05-10 09:53:28 -------------------------------- @bagder And if they don't it's happy a day. Also just realised any services that send 2FA code in email are doing things very bad. X_1523961436858372098->X_1523964428102041602 X_1523967810166304770 MyIgel 2022-05-10 10:06:54 -------------------------------- @confuzd_ @fluepke Afaik it also works on objects but yeah, it's great, 10/10, would add another dependency of i save some characters writing it by my own X_1523963671650656256->X_1523967810166304770 X_1523965802449457153 fluepke 2022-05-10 09:58:55 -------------------------------- @_michaelknoch Okay, disregarding usefulness in ancient times, this thing still gets 5.8M downloads weekly. X_1523963793851756545->X_1523965802449457153 X_1524013698939076609 tc_nj7 2022-05-10 13:09:15 -------------------------------- @beeradmoore @bagder Don't you need to have compromised that email account or the server for that attack? How does that attack work? X_1523964428102041602->X_1524013698939076609 X_1523972699684548609 tluzat 2022-05-10 10:26:20 -------------------------------- @fluepke @_michaelknoch Transitive dependencies probably account for many downloads. Also, not much incentive to rewrite each(foo, (k, v) => { /* ... */ }) as Object.entries(foo).forEach(([k, v]) => { /* ... */ }) while losing support for some environments. X_1523965802449457153->X_1523972699684548609 X_1523976410808922114 _michaelknoch 2022-05-10 10:41:05 -------------------------------- @fluepke hopefully legacy X_1523965802449457153->X_1523976410808922114 X_1524001475638276100 GeeItSomeLaldy 2022-05-10 12:20:41 -------------------------------- @tluzat @mikiemeatsweats @lrvick @heavilyarmedc Hijacking a common ES3 shim package. Evil. X_1523965958242680832->X_1524001475638276100 X_1523994978669711360 ryancdotorg 2022-05-10 11:54:52 -------------------------------- @agowa338 @lrvick It was a satirical proposal, not actually implemented. X_1523971998912819202->X_1523994978669711360 X_1523983459374571526 MalphasWats 2022-05-10 11:09:05 -------------------------------- @eevee Stories like this are why Node gives me The Ick. X_1523977844170366977->X_1523983459374571526 X_1523985720158744576 walkerjian 2022-05-10 11:18:04 -------------------------------- @eevee do you know who i am eeVee? X_1523977844170366977->X_1523985720158744576 X_1523982714172547073 vxunderground 2022-05-10 11:06:07 -------------------------------- .@lrvick bought the expired domain name for the 'foreach' NPM package maintainer. He now controls the package which 2.2m packages depend on. Information via @cyb3rops https://t.co/ZPd7sgDV2g X_1523983787356475392 vxunderground 2022-05-10 11:10:23 -------------------------------- @lrvick @cyb3rops 2.2m projects and/or code repositories** vx-underground, poor phrasing final boss, inventor of the typographical error X_1523982714172547073->X_1523983787356475392 X_1523984679917035521 Ciccio_87XX 2022-05-10 11:13:56 -------------------------------- @vxunderground @lrvick @cyb3rops All, of JS ecosystem is utter shitshow. X_1523982714172547073->X_1523984679917035521 X_1523985242842873858 DCoderLT 2022-05-10 11:16:10 -------------------------------- Dibs on the package called 'while'. Always love a reminder of what a dumpster fire npm is. https://t.co/7gDktZB8v3 X_1523982714172547073->X_1523985242842873858 quoted by X_1523985403832795136 notduck1e 2022-05-10 11:16:49 -------------------------------- @vxunderground @lrvick @cyb3rops do a node ipc like ransomware attack X_1523982714172547073->X_1523985403832795136 X_1523988256026767362 rhensing 2022-05-10 11:28:09 -------------------------------- They tell me this is how the world ends. https://t.co/mKf4lP86dF X_1523982714172547073->X_1523988256026767362 quoted by X_1523988275085684736 iam_py_test 2022-05-10 11:28:13 -------------------------------- That shows how easy it is to take over an NPM package https://t.co/lLlaoS3lb7 X_1523982714172547073->X_1523988275085684736 quoted by X_1523996285522833408 YousukezanT 2022-05-10 12:00:03 -------------------------------- Categorized: https://t.co/G7VdsuPacq X_1523982714172547073->X_1523996285522833408 quoted by X_1523997545596436483 Bandrel 2022-05-10 12:05:04 -------------------------------- https://t.co/ghumw54vSx X_1523982714172547073->X_1523997545596436483 quoted by X_1523999228187529216 cneitzert 2022-05-10 12:11:45 -------------------------------- ...if GNU or FOSS #supplychain #security wasn't nightmare fuel for you before today... https://t.co/gVWOGnPGNj X_1523982714172547073->X_1523999228187529216 quoted by X_1524000267481477120 d_ennistan 2022-05-10 12:15:52 -------------------------------- @vxunderground @lrvick @cyb3rops A hero we do not deserved. X_1523982714172547073->X_1524000267481477120 X_1524001275255619584 joelpmichael 2022-05-10 12:19:53 -------------------------------- Hoooooooooly shiiiiiiittttttttttt And you thought log4j was bad... https://t.co/gigMGFBMym X_1523982714172547073->X_1524001275255619584 quoted by X_1524004034079731712 seandakid 2022-05-10 12:30:51 -------------------------------- @vxunderground @lrvick @cyb3rops Nice hit. X_1523982714172547073->X_1524004034079731712 X_1524015168623194113 tinycommercial 2022-05-10 13:15:05 -------------------------------- tenho uma opiniao mt forte sobre isso mas n irei expressa-la https://t.co/g8qJEWRpHs X_1523982714172547073->X_1524015168623194113 quoted by X_1524025715951386626 filipedfr 2022-05-10 13:57:00 -------------------------------- Wow https://t.co/gKHxiZQFGa X_1523982714172547073->X_1524025715951386626 quoted by X_1523990625976209409 rhysmorgan 2022-05-10 11:37:34 -------------------------------- @vxunderground @lrvick @cyb3rops Why does forEach even exist as a separate npm package!? Everything I read suggests that Array.prototype.forEach() existed and is supported in earlier versions of browsers than that npm package. X_1523983787356475392->X_1523990625976209409 X_1524023884894384128 ov3rflow1 2022-05-10 13:49:43 -------------------------------- @vxunderground @lrvick @cyb3rops [?] https://t.co/Yn2ye4bQeO X_1523983787356475392->X_1524023884894384128 X_1523987951134429185 urlocalnonbinry 2022-05-10 11:26:56 -------------------------------- @Ciccio_87XX @vxunderground @lrvick @cyb3rops I'd argue these kinds of attacks are possible with other package managers. NPM is just the most popular. X_1523984679917035521->X_1523987951134429185 X_1524009018473164800 eevee 2022-05-10 12:50:39 -------------------------------- @walkerjian no X_1523985720158744576->X_1524009018473164800 X_1523989497234526209 vrillly 2022-05-10 11:33:05 -------------------------------- @urlocalnonbinry @Ciccio_87XX @vxunderground @lrvick @cyb3rops Every other package manager has this magic code signing feature ;) X_1523987951134429185->X_1523989497234526209 X_1523989760280350721 Ciccio_87XX 2022-05-10 11:34:07 -------------------------------- @urlocalnonbinry @vxunderground @lrvick @cyb3rops Well, surely, and it's not NPM, it's JS community, where else have you seen dependencies on a "isOdd" package? X_1523987951134429185->X_1523989760280350721 X_1523993702233948162 NSCUpdate 2022-05-10 11:49:47 -------------------------------- https://t.co/BYEVJ06VbJ X_1523988275085684736->X_1523993702233948162 quoted by X_1523990053361434625 Ciccio_87XX 2022-05-10 11:35:17 -------------------------------- @vrillly @urlocalnonbinry @vxunderground @lrvick @cyb3rops Yep, that's why I wrote JS, not Node/NPM https://t.co/Fb2NKpQg6u X_1523989497234526209->X_1523990053361434625 X_1523996319517483010 urlocalnonbinry 2022-05-10 12:00:11 -------------------------------- @vrillly @Ciccio_87XX @vxunderground @lrvick @cyb3rops In that case I retract my statement, lol. What the fuck. X_1523989497234526209->X_1523996319517483010 X_1523989760280350721->X_1523990053361434625 quoted by X_1523996737509154817 urlocalnonbinry 2022-05-10 12:01:51 -------------------------------- @Ciccio_87XX @vxunderground @lrvick @cyb3rops I think it's still driven by how many people use JS. Business pushing for quicker and quicker delivery, making devs focus on external packages. Not saying it's good, but I wouldn't be surprised if another package manager got really popular and had the same issues. X_1523989760280350721->X_1523996737509154817 X_1523991566469246978 ChristianKuehn 2022-05-10 11:41:18 -------------------------------- I mean obviously this happens, however the writeup is great :) X_1523990183645007873->X_1523991566469246978 X_1524022794337624064 ov3rflow1 2022-05-10 13:45:23 -------------------------------- @rhysmorgan @vxunderground @lrvick @cyb3rops devops basado en framewoks, librerias y paquetes de terceros se ha impuesto en web3.0 asi que javascript, php o jsp/java ahora es sumamente raro verlo en manera pura y dura. lulz por el efecto domino que esto implica. X_1523990625976209409->X_1524022794337624064 X_1524000292064346112 agowa338 2022-05-10 12:15:58 -------------------------------- @ryancdotorg @lrvick Really? Or were there multiple? Because the one I read about was serious and at least paid in one case... X_1523994978669711360->X_1524000292064346112 X_1523999514948161537 _ProtocolPolice 2022-05-10 12:12:53 -------------------------------- #hackjetoekomstopschool .. 2.2m https://t.co/NixLADwjgS https://t.co/vZyBuetgpM X_1523997545596436483->X_1523999514948161537 quoted by X_1524000505852096513 sickcodes 2022-05-10 12:16:49 -------------------------------- @NetGlitch @lrvick Ruby gems are an untouched gem X_1523998858732310529->X_1524000505852096513 X_1524004973083865090 InfoSecDJ 2022-05-10 12:34:34 -------------------------------- @0xtosh Oh but it will, and probably more than one. Remember, the motto of budget spending is "never proactive, forever reactive" X_1523998944883261445->X_1524004973083865090 X_1524009445616979969 subm3rge 2022-05-10 12:52:21 -------------------------------- @cneitzert No worries we'll just decomm that package right out of PROD... https://t.co/AE5lDlAO4m X_1523999228187529216->X_1524009445616979969 X_1524016262388531201 MylesBorins 2022-05-10 13:19:26 -------------------------------- @agowa338 @ryancdotorg @lrvick It was definitely a fun read, but it wouldn't actually be possible due to our unpublish policy https://t.co/5jCAqsXDnW X_1524000292064346112->X_1524016262388531201 X_1524000837223301121 NetGlitch 2022-05-10 12:18:08 -------------------------------- @sickcodes @lrvick Is that because they're called gems and nobody touches them? Not much into ruby, though. X_1524000505852096513->X_1524000837223301121 X_1524001620584910848 sickcodes 2022-05-10 12:21:15 -------------------------------- @NetGlitch @lrvick https://t.co/FIVhyizPXe https://t.co/bQ4WS3QTyG X_1524000837223301121->X_1524001620584910848 X_1524002488332197888 voltagex 2022-05-10 12:24:42 -------------------------------- @joelpmichael Tweet downthread suggests it's a known attack and https://t.co/MueQrZA5TV protects against it. X_1524001275255619584->X_1524002488332197888 X_1524002073968357383 NetGlitch 2022-05-10 12:23:03 -------------------------------- @sickcodes @lrvick Not exactly sure what you are trying to tell me here. Personally I think pypi is doing quite an OK job. X_1524001620584910848->X_1524002073968357383 X_1524002737603727362 o0RbR0o 2022-05-10 12:25:41 -------------------------------- @MylesBorins @lrvick These methods are known and available for years. Why should anyone who'd want to help npm on a volunteer basis want to do this in non-disclosure? Why would someone legally agree to shut up about issues they found in their free time and take those handcuffs?! X_1524001754723069952->X_1524002737603727362 X_1524008918430765057 RoyFPBentley 2022-05-10 12:50:15 -------------------------------- @NetGlitch @sickcodes @lrvick pip's dependency solver, tho :( X_1524002073968357383->X_1524008918430765057 X_1524002488332197888->X_1524002666510417921 X_1524003702029406208 o0RbR0o 2022-05-10 12:29:31 -------------------------------- @MylesBorins @lrvick It's these problems why I can't use npm or anything showing similar policies. People trying to improve your product without getting paid a thing and you basically tell them "shhhh. only tell us and then stfu forever" which will improve shit. Sorry. X_1524002737603727362->X_1524003702029406208 X_1524003589332652033 lbenedix 2022-05-10 12:29:04 -------------------------------- @fluepke it's getting worse https://t.co/k5652SB642 https://t.co/EjZKRLtwWM X_1524003350458609665->X_1524003589332652033 X_1524013148784799745 MylesBorins 2022-05-10 13:07:04 -------------------------------- @o0RbR0o @lrvick To be clear, there was no account takeover that took place. The email address with the expired domain is not associated with any existing npm accounts. If it had, we do have remediations in place that should have made this attack not viable. X_1524003702029406208->X_1524013148784799745 X_1524008214979018753 m1keil 2022-05-10 12:47:27 -------------------------------- @jschauma https://t.co/oFGGrYPcFD X_1524004567616212992->X_1524008214979018753 X_1524009777600544768 sickcodes 2022-05-10 12:53:40 -------------------------------- @RoyFPBentley @NetGlitch @lrvick Google has us covered LOL https://t.co/MPTpZWgyP9 https://t.co/0cc5o0v9E3 X_1524008918430765057->X_1524009777600544768 X_1524010467450290176 sickcodes 2022-05-10 12:56:24 -------------------------------- Supply chain isn't even a risk, just close your eyes and import. go get 810,000 packages! Oh I forgot go get was deprecated anyway https://t.co/VfeMWcGSlE X_1524009777600544768->X_1524010467450290176 quoted by X_1524017750103965697 SubitusNex 2022-05-10 13:25:21 -------------------------------- @tarah Ah, the wonders of OSS. X_1524011074546241538->X_1524017750103965697 X_1524013658107523073 MylesBorins 2022-05-10 13:09:05 -------------------------------- @o0RbR0o @lrvick Pointing towards the vulnerability program was intended to encourage responsible disclosure if new ways of compromising accounts was found, not at all to be passive aggressive or to stifle discussion. That said I'm always open to feedback! X_1524013148784799745->X_1524013658107523073 X_1524013809253462016 MylesBorins 2022-05-10 13:09:41 -------------------------------- @o0RbR0o @lrvick Talking about security related stuff, especially when a certain amount of the protection comes through obscurity, is super hard. Even harder when we have to think about respecting customer privacy and what details can or cannot be shared. X_1524013658107523073->X_1524013809253462016 X_1524014222652416005 MylesBorins 2022-05-10 13:11:20 -------------------------------- @o0RbR0o @lrvick The thread you responded to resulted in a scheduled call with @lrvick where we are going to be discussing npm's roadmap and I'll hopefully learn a few things about other things we can prioritize. My only goal here is to secure JavaScript X_1524013809253462016->X_1524014222652416005 X_1524038389934219264 SoakRonald 2022-05-10 14:47:22 -------------------------------- @GabriellaG439 @dhall_lang This is great! Thanks for sharing :) X_1524020528373108736->X_1524038389934219264 X_1524022309685964800 toastal 2022-05-10 13:43:28 -------------------------------- @GabriellaG439 @dhall_lang Dhall is a gem (no pun intended); and I really wish I could see it have more uptake. X_1524020528373108736->X_1524022309685964800 X_1524031009087500288 tcarrascoo 2022-05-10 14:18:02 -------------------------------- @filipedfr Woow ng entende nada X_1524025715951386626->X_1524031009087500288 X_1524017109705142274 agowa338 2022-05-10 13:22:48 -------------------------------- @MylesBorins @ryancdotorg @lrvick Just DMCA it then? X_1524016262388531201->X_1524017109705142274 X_1524017952730849282 SubitusNex 2022-05-10 13:26:09 -------------------------------- @tarah Didn't know we had actual pictures taken of log4j X_1524017750103965697->X_1524017952730849282 X_1524038710173466624 GabriellaG439 2022-05-10 14:48:38 -------------------------------- @SoakRonald @dhall_lang You're welcome! X_1524038389934219264->X_1524038710173466624 X_1524019327166554121 MylesBorins 2022-05-10 13:31:37 -------------------------------- @agowa338 @ryancdotorg @lrvick This is why we can't have nice things X_1524017109705142274->X_1524019327166554121