RIP Open Sores

theregister.co.uk/2018/11/26/npm_repo_bitcoin_stealer/

medium.com/@jsoverson/exploiting-developer-infrastructure-is-insanely-easy-9849937e81d4

arstechnica.com/information-technology/2018/11/hacker-backdoors-widely-used-open-source-software-to-steal-bitcoin/

>Open source, as it has grown, is broken and the larger it grows the more likely that catastrophic events will occur. Given the potential for damage with this exploit, the fact that it was so limited is a blessing. It’s also not limited to node.js or npm, there is just as much misplaced trust in sister ecosystems like Python’s pypi and Ruby’s gems and with Github as a service itself. Anyone can publish to these and control can change without any notice. Even without a change of control, there’s so much code that thoroughly vetting it all in the first place would grind any team to a halt. In order to meet timelines, developers install what they need to install and security teams and automated tools just aren’t able to adapt to the pace at which software changes.

Open source was a mistake.

Attached: fglt.png (707x865, 72K)

Other urls found in this thread:

torrentfreak.com/utorrent-quietly-installs-riskware-bitcoin-miner-users-report-150306/
extremetech.com/mobile/247026-android-surpasses-windows-used-operating-system-worldwide
twitter.com/NSFWRedditVideo

Wrong. It's the users' fault for not auditing all 37,000,000 lines of code in the dependency tree before deploying it.

open sores and buttcoiners btfo

Why the hell do you think we don't want systemd?
No one can audit that shit and now almost everything depends by default on some redhat shit.

What you meant is that npm and the mentality and ecosystem it created was a mistake.

Equivocation
NPM was a mistake, not open source.

>consume
>consume
>consume
what the fuck has been consumed?

>Open source was a mistake.
Had this been closed sourced, it would never be made public and possibly, companies wouldn't bother fixing it because it would cost more money and resources.
Fuck off with your FUD.

>boohoo someone made software for free and I used it but he doesn't want to maintain it anymore
Just fork it instead of being a faggot. They shouldn't update mindlessly

>the broken javascript ecosystem broke again
>somehow this is the fault of open source
"news" shadow written by Steve Ballmer