Unlikely.
> undermines the ecosystem due to the loss of trust.
Good, that trust was always misplaced. At least it’s only Russia and Belarus getting screwed instead of everybody getting hit by ransomware.
Unlikely.
> undermines the ecosystem due to the loss of trust.
Good, that trust was always misplaced. At least it’s only Russia and Belarus getting screwed instead of everybody getting hit by ransomware.
* Despite the motive for the act there is actual malicious code injected in a library without notifying or disclosing any information.
* The whole act was not well thought out. The check is rudimentary to put it gently, or plain naive to say it straight. Not only Russians are targeted but also anyone having vpns or other legitimate reasons to run under Russian IPs. Finally the check is crude and might as well fail at some point, with devastating effect.
* Author seems to be removing github issues, hiding conversations and doing damage control now that this backfires.
“FOSS developer” is hardly a career. Nobody is losing out on income by you blacklisting their projects.
The most obvious is former Soviet republics, or any neighbour of a target nation, being mis-identified. That includes Ukraine itself, by the way, but also Finland and Poland. How about territory that is disputed? Or adjacent to enclaves like Kaliningrad? But it can also include friendly-nation assets that just happen to be currently inside Russia or Belarus, including government entities and journalists. It can affect folks simply relying on mobile networks near borders. Address blocks are routinely reallocated, reassigned, reused, misused, on a global basis and an address range announced in Korea last year can show up in Canada tomorrow.
Even geolocation by client-side request can be wrong, too. Not just because it's easy to lie, but major nations also fuck with the GPS, which is an issue currently affecting Baltic aviation¹. By the same token, IP geolocation databases are easily misled by self-reporting from mobile devices. Simple example: imagine someone using a dedicated VPS in the US as a personal VPN exit node for their devices when visiting mainland China (actually, we don't have to imagine: I did exactly this). Any IP-based location assumptions start out incorrect, since it's by VPN exit IP; but later on, thanks to mobile device reporting, that IP address can end up misclassified long-term as "Chinese".
None of this is hypothetical. I visited Jordan a few years ago and whilst visiting ruins near Umm Qais, up by the Sea of Galilee, my phone was switching to Israeli networks. I also know of an Australian startup that was mis-identified as Russian and lost access to a major partner API². That's since resolved, but the point is, forget what you see on police procedurals; identifying the political jurisdiction of a device, whether it's by IP address or any other means, remains an art, not a science, and it's incredibly easy to be wrong.
As for the suggestion that the rest of us remain unaffected; any malware incident in the node ecosystem requires immediate attention and audit from every security team, whether you were the intended target or not. This idiot has cost all of us time and energy.
[1] https://www.theguardian.com/world/2022/mar/09/finland-gps-di...
[2] https://twitter.com/cyclytics/status/1503211938133966851
The truth is that you are the idiot if you only perform audits when someone else announces an incident. You’ve already lost at that point.
It’s nobody else’s fault but yours if you waste time because of your shit policies.
But go on, keep digging an ever deeper hole for yourself with pathetic attempts at shifting blame. It’s absolutely your security teams job to audit all incoming code, rather than blindly trusting stuff from NPM.
Because: we already do routine malware scanning and audit, and review of every changing dependency that we know of, and their transitive dependencies. The scale and frequency of change is one of the reasons to minimise exposure to the fragmented, chaotic shitshow of the node ecosystem.
When there's an incident - and this is most definitely an incident - we have to do more work to verify there was no inadvertent occurrence, that it did not slip through, etc etc.
What's more, one must necessarily download the shit to inspect it, which means you're potentially now holding an unexploded bomb sitting in your developer laptop, for which possibly the only mitigation is that it's sitting inside a container or virtual machine, and one must be careful not to trigger it.
Due to the destruction of trust, we'll also be making an additional effort to remove and replace this and any other package from the same author, and any repository to which they have contributed has to be considered potentially tainted and subject to additional review.
Since you didn't apparently know any of this, I don't think you have any standing to comment on security team procedures.
>This is doubling down with more poorly considered assumptions and demonstrating an overwhelming lack of knowledge about security process
Sorry, but no. I’ve worked in this field for two decades. What you’re describing is meaningless security theatre meant to appease the people paying your salaries.
And for what it’s worth, you started it with the insults and silly appeals to authority.
I’ve also just realised you’re the same nutter who was desperate to prove Bill Woodcock doesn’t have (and I quote) ”basic understanding of DNS”.
Ok, I’m done smacking this particular witless, flailing troll around. Be seeing you.
Bill Woodcock got the technical details utterly wrong. His track record doesn’t matter when he’s spewing out bullshit, it’s still just that.
Just read your comments again https://news.ycombinator.com/item?id=30513375
You were trying to argue that pulling out root nameservers from Russia would be a bad thing because … Roskomnadzor can only restrict access to foreign DNS servers?
And you call me deluded.
Fairly sure you don't know what that phrase means. Whose authority, exactly? I'll appeal to my own, I suppose, but that is because I actually know what I'm talking about.
Definitely sure you don't have anything to say, but are committed to telling people they're stupid because ... you have little else to contribute, and are stuck in a muddy trench of incoherent rage you dug for yourself. Again.
Read our previous conversation, your comments were about Woodcocks background up until you wanted to change the topic entirely to discuss Russian internet censorship. You were completely unable to come up with a coherent technical explanation as to why Bill wasn’t wrong when he said what he did.
> I suppose, but that is because I actually know what I'm talking about.
That’s it. You can’t supply any useful facts, everything that comes out of your mouth is supposed to be the truth because you are an expert.
Yet, your Linkedin makes it pretty clear that you are a nobody. Just a perpetual software developer and occasional low level manager without any real achievements in his life.
I tried very hard to dig a fact based argument out of you, but I think you know very well that you’re defending bad policy.
The idea that declaring an “incident” over something like this is actually necessary, rather than just a move to appease questions from management is completely frivolous. If you were serious about your security posture, you’d be prepared for these events in the first place.
Trusting NPM is inevitably going to get you hacked.
> are stuck in a muddy trench of incoherent rage you dug for yourself. Again.
Read your own comments, they’re the incoherent ramblings of a crackhead.
> Definitely sure you don't have anything to say, but are committed to telling people they're stupid because
Look in the mirror, you were the first person in this conversation to use words like “idiot”. I merely suggested that the word would be better applied to you.
Past explanations here: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
The flamewar itself was bad on both your parts, and you definitely both broke the site guidelines repeatedly (not cool!), and you both should stop posting like that because we ban accounts that keep posting like that.
> 2) Shut down the root nameservers inside Russia. That would make connectivity spotty for many users inside Russia, but mostly regular folks, not government or military users.
That’s just not true. Shutting down root nameservers inside Russia would not make anyones connection spotty in any meaningful way.
How would that even work? It’s not like sending root NS queries abroad is a big deal, especially since most people will be using ISP nameservers and have those replies cached anyway.
Also
> In the short-term, this is a bad plan because it would cut the Russian man-on-the-street off from international news and perspectives, leaving them with only what the Russian government chooses to tell them. That's not a great way to decrease Russian public support for the war.
This wouldn’t be a consequence of any of the things you listed. International news don’t live on .ru TLD, they don’t depend on domestic root nameservers or Russian IP allocations either.