My entire PC got wiped Do not download
github.com
github.com
I would love for pro-“special operation” Russians to find out why Ukrainian hospitals in the war zone keep their lights off at night. Hint: so they won’t be targeted. Spreading those truths could have done some good, but this… this is merely malicious.
You could say exactly the same about economic sanctions, no?
The idea that spreading information about Russian war crimes in Ukraine will somehow lead to a popular uprising is really far fetched.
Instead what did happened was the imprisonments of the journalist Julian Assange.
In the age we live in most citizens, in any country, are powerless, if you peacefully speak up against your own regime you will be doxxed, silenced, arrested, your bank accounts frozen and even be classified as a terrorist. This have been the case in authoritarian countries but now also is common in so called democratic countries too.
Thinking that you create massive change in another country by putting sanctions on that citizenry is naive, not only will they be punished for the sanctions itself but also when speaking up.
> this ... now also is common in so called democratic countries too
Uh, in what democratic countries, exactly?
Canada (terrorist, bank accounts frozen)
USA (no fly list, bank accounts closed)
Sweden & Austria (bank accounts closed)
All this with any court order.
Doxxing and silencing is done by groups closely related to the regime, e.g. gets funding, like media and ngos.
Economic sanctions target sectors.
Average Russians not eating McDonald's is not the target of sanctions. Profit from food sales then going to oligarchs and supporting the military is.
This package does more harm to the McDonald's eating crowd....
This isn’t a videogame dropping wiper malware, but business software.
So no, I don’t see how this is supposed to harm the McDonald’s eating crowd any more than sanctions do.
Therefore, I argue that the user is harmed more than the business.
To compare, I believe average Russians are more impacted in terms of the amount of money that they can access freely, based upon the video that I added in my initial response to your comment, above.
But I also think to some extent it’s only fair that the regular people pay a price for the war. Not necessarily a very steep one, but a price nonetheless.
Presuming that the goal is for Russia to stop and roll back its invasion of Ukraine, the sanctions that have Frozen basically all international currency interactions with Russia.
The node IPC rewrite, to destroy data of business systems, seems unlike anything that you and I have talked about so far in the subthread, and instead seems more like a malicious way to cripple and permanently harm users. Their data which they have entrusted with the businesses now potentially all trashed. It's certainly not like anything which my government, the US government, has publicly discussed doing against Russia in response to this invasion. It's frankly an illegal action by the node IPC owner based on my understanding of computer crimes.
It's absolutely categorically illegal - hell, look at what Aaron Swartz was prosecuted for - and I have no doubt that they'll throw the book at him. This is way beyond the pale. It's not a 'no jury in the land' case like that Ukrainian crewman sinking the oligarch's yacht.
In Swartz’s case it wasn’t at all obvious to an outsider how many people would be upset, but there certainly were big domestic interests in favour of prosecuting him. Positive EV for the prosecutor.
Here? You’ll find little serious support for bringing charges, but the chances of the story being spun in a way that casts a very negative light on the government are high.
While I don’t agree in principle, you could easily paint this man as a hero for striking against a war-mongering country that lets their ransomware gangs attack American hospitals and other critical infrastructure with impunity.
Prosecutors worry more about career progression than juries, cases like this have a negative expected value.
> software developers are smart enough to not download crap from the internet, but they will gladly run npm install with full user privileges.
I think there's an overton window here which is getting pushed. People need to stop unilaterally imposing their own form of punishment to a group of people, just to make a political statement.
It was bad with the BLM saga, but apparently at the time, it was too politically incorrect to say. It is still bad now that the russian invasion is causing an even wider and larger number of such malware.
Make political statements with your government, or do it as a standalone organization. Put ads in the papers, media etc. Don't use an unrelated platform, such as software distribution platforms to make a political statement - esp. if it harms the end user in some ways. There's a name for such action - it's called terrorism. I would hope that the people living in civilized society can see that.
Is the implication that there is/was pro-BLM malware floating around? I've not heard of anything even remotely similar?
License changes are not malware.
They never went away, you just don't hear about them because they don't publicly pat themselves on the back every time they signal their virtue...
Though I wish the "anti woke" would see that this helps nobody who is actually marginalized, it's just feel good for naive liberals. Companies for which inclusion and diversity is less than a slogan exist, but they are very far and few between.
We'd rather want safe access to healthcare than corporations throwing pride flags on their logo until exactly midnight of the next month once a year. Thanks.
The point I wanted to make is that I know of the same companies described above how they let 'minor infractions' from some individuals pass. Minor infractions being quotes like 'Women belong in the kitchen', dick pics, and questioning non binary people if they just need to be with a real man for once.
I found wokeness more often than not to be the social greenwashing of our time.
In one place I was extremely happy to be able to work remote, becauase using bathrooms in their office (either, really) turned into rolling a dice of risking awkward confrontation always brushed off when I dared talk about it in my HR JF. Sometimes these conversations turn comical, because the "direction" I'm transitioning isn't obvious to some people, leading me into being gatekept from the _wrong_ facility.
Of course that problem exists in most public places as a non-passing trans person, but I'd at least be spared from this at work.
I know there is no "cookbook" of talking to other people. But sometimes I wish to me it were more easy to share and learn.
Thankfully a few months later there was a change of leadership, and my name was changed in Slack/AD with no problems whatsoever.
1: https://www.charta-der-vielfalt.de/uploads/tx_dreipccdvdiver...
If you purposely distribute malware you don't get to be part of the package registry as you have proven you can't handle the responsibility.
>We do not allow anyone to use our platform in direct support of unlawful attacks that cause technical harms, such as using GitHub as a means to deliver malicious executables or as attack infrastructure
Why are they still hosting this? It would seem to violate the CFAA and therefore be unlawful
But I don't understand why/how it would wipe the PC. Unless I missed something, the code from the package does not delete anything.
> This code serves as a non-destructive example of why controlling your node modules is important. It also serves as a non-violent protest against Russia's aggression that threatens the world right now.
Nah, the author knew it's would be controversial. The first sentence is there as an excuse.
https://gist.github.com/MidSpike/f7ae3457420af78a54b38a31cc0...
It does not delete anything, just rewrite them.. Which is much more terrible than just deleting.
I forked the repo to make the README.md more accurate and satirical (and removed the actual malicious code), but sadly I can't make a PR since he's locked down the repository to only contributors.
https://github.com/4oo4/cyberwarfareispeace
But seriously GitHub and NPM, get your shit together.
EDIT: Finally got a response back from NPM and GitHub that they're investigating.
https://github.com/advisories/GHSA-97m3-w2cp-4xx6
I asked them for clarification.
Blaming citizens who are mostly uninformed and mislead due to information control, and have little real power to change what's happening, doesn't help at all to the current situation.
Probabilistic Justice isn't just
If one random supporter of the current thing can cause such a mayhem, imagine what can happen to any of the projects in 2-3 years: you run update and find your sever wiped out because capitalism is bad or indigenous people of Tuvalu lost a fishing boat or whatever.
On the longer run this is the end of community projects in mission critical applications.
You are one brain damaging soy latte away from total distaster.
And even if you ignore that: what about the browser you use to install it? The library you use to decompress the file? The library you use to checksum it? The dependencies you install when you write code in .NET (which is the entire problem here and is literally no different whatsoever in .NET, aside perhaps from differences in the size of their standard libraries)?
I'm sorry, you're right to say that this is wrong and that the ease of installing malware is terrifying (and not nearly enough acknowledged), but there's no lazy magic bullet that will save you. Welcome to combinatorial explosion!
Another suitable mitigation strategy may be lock dependencies version or switch to other programming languages with a proper standard library and limited number of packages where one can at least audit the code.
But you’re probably looking for something more general, like containers, virtual machines, or other sandboxes (chroot?).
yarn install --flat
git add node_modules
Then the next time you run yarn upgrade: yarn upgrade --flat
git diff
Carefully read through what changed in each of the packages. git add node_packages
git commit -m "yarn upgrade"
You will see a lot of bad code, but also learn stuff. But most importantly - your project will be secure.Keep backups on an external file store just in case.
Use a filesystem that has snapshot capabilities.
Snapshots on an external system is useful but few are disciplined enough to take regular enough snapshots.
I'd argue the root/normal user separation is largely useless on single user desktop computers.
You want a world where a browser exploit can drop a bootkit? Nahhh
Don't download, install and run random code libraries from the internet, assume they are hostile until proven otherwise.
As horrible and impracticable as it sounds, the only way to prevent this happening is to read the source of every (/transitive) dependency you install. Yes, we can trust people, and yes, we can blame them when they betray our trust - we can even prosecute them - but as this shows, that's not always going to stop people. And it's certainly not going to stop attackers who gain control of those dependencies.
This is something we really need to think about as a profession. I would favour a system where dependencies are restricted to pure computation only (no syscalls) and any greater permissions must be granted explicitly. But that's extremely onerous, and likely - for many devs - to lead to a 'just click yes' mentality; even besides that, there are doubtless many cases it won't prevent. All I'm sure of is that we can't continue like this.
npm i --before=`date -I -d '-5 days'`
It will only install packages released before the specified date.[0] In fact, it doesn't specify this flag at all. Nor does the command line help, or man page. It doesn't say a word about this, and it appears the only way to determine the semantics of this flag is to run it.
https://github.com/RIAEvangelist/node-ipc/commit/088a1ca4d5f...
This is why you should pin dependencies, but good luck keeping up with that in modern Javascript dependency hell where every framework pulls in half a gigabyte of dependencies.