NPM won't publish packages containing the word keygen
mamot.fr
mamot.fr
But no. Just a few years ago I tried to enter an answer into a Hungarian Q&A site recommending to take the Algeciras-Tangier ferry and the answer was refused. https://en.wiktionary.org/wiki/geci
If airports, phones, and corner shops claimed they 'work in crypto' it would be similarly misleading.
Even Toly refers to himself as a distributed systems engineer, because building a blockchain involves more DS work than crypto work.
FWIW I work in web3/defi, used to work in PKI.
Sometimes being there first doesn't mean you get to use the simplification forever. Cryptography is an older thing than cryptocurrency, but both are unwieldy to pronounce and have been simplified to "crypto". Since cryptography is math and cryptocurrencies (in the "popular" sphere) is a get rich quick scheme, the abbreviation that works for both generally became applied to the latter.
I am sure organic chemists are a little weirded out when people tell them "oh yeah I love those new strawberries we got". This is that.
Usage varies, but "bint" more commonly is akin to "b*tch", and is used in a very coarse and derogatory manner.
Love how you're trying to justify degrees of acceptable misogynist terms, though /s
How come you're unwilling to spell the word bitch?
Why else do you spell out one word but censor the other?
One is much more likely to set off censors. Why do you feel the need to ask ridiculous questions? The word you use had already been said, censoring it would be meaningless -- whereas you ascertained the word I meant easily ;)
In fact, if you note, I’ve never actually used either word. I just refer to them obliquely.
I never claimed either were acceptable or unacceptable.
Interesting how you completely gloss over your needless language policing, especially when you - by your own admission -- haven't even used the terms in question (and presumably lack the nuance necessary to weigh in, despite jumping in anyway) shrug
and
> Love how you're trying to justify degrees of acceptable misogynist terms
So you are not saying either are unacceptable, and you endorse 'acceptable' misogyny. So you are a misogynist, but an ok one.
Very well.
The only one "endorsing" misogyny here is you. Stop projecting, pillock.
(For those not getting the specific one used above, Lovecraft had a black cat and a common name for black cats at the time combined a now nigh-unprintable racial slur for black people with the word 'man'.)
There are people that fail the test, too - such as people who think that the terms "whitelist" and "blacklist" are offensive.
- npm sends images you view online to GitHub
- vscode bakes a VPN into npm and turns it on
- The dark defaults of npm
- vscode records editing (browsing) history in InPrivate mode
Azure or OpenAI seem even worse. And Windows has a lot of Edge-like things built into it, including how it tries to get users to use Edge.
You couldn’t say shit on the internet. I mean what the fuck.
But english mostly ignores long vowels, hence the alternate spelling.
For those of you who want to have a better handle on the distinction, you can think of it as the sound having an extra 'beat', where a beat is the amount of time pronouncing that sound normally occupies.
It's easier if you take advantage of the one place English still distinguishes this: word boundaries.
Listen how you say, for example: Tibetan nitwit (you're holding the 'n' for two beats because your brain treats the distinction as important /when it's at a word boundary). You can do this with vowels too as an exercise, though they're a bit harder because English has a lot of vowels and finding good matches is a bit difficult.
[^0]: https://keygen.sh
Three fun days of CI/CD pipeline debugging to get to this..
But it doesn't look like it's searchable, unless there's a caching issue.
Sure no one will be able to install the app from the CLI (unless there is a bug in npm’s parsing logic) but you should be fine distributing hyperlinks to skim-readers ;)
Code samples are usually more relevant than marketing messages.
(I wasn't expecting so much traffic and feedback today lol)
keygen genkey
Can't do genkey genkey. That's just weird... genkey keygenkek is orc for lol.
Thank God I didn't lol.
KeyDjinn
Or
Keygyn
Get in that extra level of possible scandal.
Either way, the logos practically make themselves.
That's why the debug information would help.
Until someone turns up with a new combo where it doesn't work. Because judging by the comments, this seems to be a janky piece of code that isn't well understood.
"Turn it off" (or rather, "rip it out, and throw it away" is good advice. If there is even a slight chance this might come back to haunt you and screw the user experience, it isn't worth it. If your animation is more important than avoiding a horrible user experience, well, that's kind of useful for your customers I suppose.
Do you want an appointment? A lab?
Good to hear it's not just me though (and the effects also aren't disabled for me either).
I haven't noticed any drop in registrations, conversions, or any noticeable differences in traffic patterns after launching the redesign, so I'm not sure if this is actually happening. Though it's a valid concern and issue, and I do want to fix it. And I appreciate all the reports. I think it may be a retina resolution issue, but could be wrong.
On launch day, everyone loved the effect (it goes along with the new logo) and only a couple people said it performed badly, but they were on exotic devices.
I may have caused this a few days ago when I enabled rendering at retina resolution for tier 3 devices. What I wasn't expecting was so many tier 3 devices that aren't really what I'd consider "tier 3." I was expecting all tier 3 devices to be gaming-level GPUs.
I guess I should have read the source [^0] more closely and I could've avoid this.
Could be the detection of GPUs doesn't work correctly? My nVidia 1080Ti is detected as nVidia 980Ti, and a sibling comment mentions an integrated laptop GPU being detected as tier 3 with isMobile=false.
Console logs: device: undefined, fps: 60, gpu: amd renoir, isMobile: false, tier: 3
FWIW, my laptop is a relatively beefy 2021 model (granted, with integrated GPU). For a business that's not about 3D rendering, spending an innovation token on making sure your landing page can have a smooth background animation seems like it's playing on hard mode.
{
"fps": 130,
"gpu": "amd radeon pro 5300m",
"isMobile": false,
"tier": 3,
"type": "BENCHMARK"
}
Definitely wasn't 130 FPS and made the whole page stuttery.Macbook Pro M1
I'm using an external monitor running at 5120x1440 (Samsung, not retina) only, and am experiencing the the same on Firefox.
At least not retina exclusive.
Despite the supposedly high FPS it's very jumpy/laggy in Firefox, though fast in Safari.
Just get rid of it entirely. The visual flair is not adding any value. It's a performance drag, highly distracting, and serves no useful purpose whatsoever. This "trend" in modern web design is truly infuriating.
I think the lava lamp effect is cool. The perf issues can and will be fixed.
(Your site works fine on my computer. The effect is disabled and it's not a problem.)
There's clearly bugs where it's enabled where it shouldn't be, and that's certainly an issue, but the comments here make it clear that it gets disabled automatically on lower-end devices.
From my perspective I agree with a lot of the other commenters - it’s just design for design’s sake. It’s an expensive way to add minor visual flair that heavily degrades the experience for a sizeable number of users. In terms of value provided to the user: it’s basically zero, or often worse than zero.
Personally, it feels over-designed, which the stretched font for the headings really reinforces. I’d drop the shader, re-evaluate your font choice for the headings, and focus on layout and readability a little more - using the site on my iPhone feels really cramped and like the whole page is getting cut off on the right-hand side constantly. I can’t scroll horizontally to see the rest of the code, for example.
I do like the little text-flicker/flipboard animation on the “keygen” logo though. That looks clean and well-suited to the theme of the site.
And it may be over-designed. It was my first foray back into design since switching careers to programming about 10 years ago. Maybe I took it a bit too far? Felt good to stretch those muscles, though. :)
Mac+Firefox users are probably in your customer base. Listen to the feedback.
The animation itself looks fine, its slow enough that it doesn't feel distracting. Just a bit of flavor.
Its mostly just a few calls to a cheap noise function and no footguns I can see. Also hurrah for dev tools and open text formats! If you're looking for better performance, it looks like the noise could be precomputed (the same blob always gets the same noise)". Might be faster, might just hit more bugs.
device: undefined
fps: 30
gpu: "intel mesa dri intel hd graphics 400"
isMobile: false
tier: 2
type: "BENCHMARK"
I’ve looked at the source, and it seems you’re doing too much computations there. Metaballs are usually rather simple, and they don’t require any trigonometric functions. Compute something like `sum( ball.z / length( pixel - ball.xy ) )` and apply the threshold. If you want anti-aliasing, use fwidth() for the screen-space partial derivative of that value after the loop, compute two thresholds around the iso-value, then smoothstep() instead of a hard threshold.
Also, consider moving the ball parameters (center and size) into a constant buffer and update them on CPU. Because there’s just a few balls, JavaScript is good enough for the job. Your current version computes these things from time for each pixel for each frame. There’re about 8 megapixels on my display, so these computation costs are escalating very quickly.
I sent you an email with a job offer.
{"CANVASES":2,"GPU":{"fps":209,"gpu":"apple m2","isMobile":false,"tier":3,"type":"BENCHMARK"},"RESOLUTION_RATIO":2,"BLOB_COUNT":20,"BLOB_AMPLITUDE":"52.60","BLOB_RADIUS":"2.54","POSITION_X":"4.43","POSITION_Y":"1.72","RANGE_X":"4.64","RANGE_Y":"6.51","SPEED_X":"9.60","SPEED_Y":"4.51"}
Sorry, that's what you get for not using a normal computer.
Nowadays though, we have a different Scunthorpe problem. I call it the "Hidden Garfield" problem, because that phrase is detected as a racial slur after you run Double Metaphone on it and throw out spaces.
It's the same as any other "this shouldn't be done, but a manager asks me to do it". If you aren't ready to die on that hill as I would, then there is nothing you can do. I'd easily take that fight but that's coming from a very privileged position (i.e., I'd not risk not having food on the table if I said no when a manager asked me to add keyword moderation or a dark-pattern cookie banner).
There's also a famous image I've seen online from another game where the guy's name was Nasser which appeared for everyone else in-game as "N***er"
Unless I've gotten confused about the limits of dynamic prediction abilities in ANS.
I think it's just that the encoder and decoder run in opposite directions through the encoded symbols, but read-ahead during decoding shouldn't be a problem...
In a similar vein, a former colleague of mine created this Python package: https://pypi.org/project/piickle/
It's functionally the same as pickle, except it binary-encodes the data with spaces and pickle emoji.
https://wow.tools/dbc/?dbc=namesprofanity&build=10.0.5.47660...
They spent great effort to build this list.
Most character names in the game are lame anyway and some are just offensive or inappropriate.
"bra" is rude.
"maxipad" is rude.
"masterbaiter" is rude and funny.
"amputee" is rude, even.
This goes far...
Their hamfisted approach leaves a lot to be desired. I have a feeling it is a product of being designed and implemented by non-native English speakers.
Every so often someone will find their sentence that contains something like "I will have ham or egg in my sandwich" becomes "I will have ham onaibun my sandwich"
If you search for some of those terms, you can still find traces of them across the internet and even in some published scientific papers.
I don't know what the filters are like in EverQuest nowadays [1], but back in 2000 EQ didn't allow "cock" in chat. Then in April 2000 the expansion "The Ruins of Kunark" came and some of the zones that pretty much everyone making their first trips to Kunark would visit contained a variety of hostile cockatrices, and the chat filter would not let you mention them because of the "cock" at the start of their names.
I once had occasion to implement a chat system for a small online gaming service and was supposed to filter out bad language. What I did was something like this:
1. Split the message into words.
2. For each word that is in /usr/share/dict/words or our own list of good words and is not on our bad words list, mark each character in that word as being good.
3. Concatenate all the words.
4. Find all places where words from the bad list appear as substrings of that concatenated string.
5. For any such bad words in the concatenated string mask the corresponding characters in the original message with asterisks unless all of the bad word's characters in the concatenated string are marked as good.
For example the word "cockatrice" would have been uncensored even if "cock" was on our bad list because "cockatrice" is in /usr/share/dict/words and would not have been on the bad list. On the other hand "cocksucker" would have had the "cock" masked.
If someone had tried to slip "cocksucker" by by inserting spaces such as "c o c k s u c k e r" the "cock" part would have still been masked, because the "c o c k" would have ended up as "cock" in the concatenated string, and not marked as good.
Note that you would have been able to call someone a "peacock sucker" just fine, because "peacock" is in /usr/share/dict/words. Misspell that as "peecock sucker" though and then the "cock" part would have been masked.
I was fine with that. I figured it encouraged good spelling among those who want to insult others. :-)
(There was a little more, such as dealing with tricks like using 3 for e or \/\/ for w but those aren't really relevant to the general idea).
[1] Yes, EQ is still around...and with the changes it has undergone over the years it is actually a pretty nice solo or small group game even on a free play account, especially if you have an old account to reactive so you get veteran rewards. Here's a description of some of the major changes [2]. When I returned to EQ a few years ago, I had no trouble playing a solo Bard to around level 60 on free play. Things got a bit slow then and I switched to paid. I then made reasonable progress up until I had finally satisfied my
It doesn't seem that hard for npm to review lists of the most common keyword searches and identify the ones strongly associated with piracy (or other things negative for their business).
I agree, though, that keyword moderation is pretty terrible. It might work from npm's perspective, in that it might be annoying enough to pirates that they'll find some more convenient place to upload/download. I don't think it will have any overall impact on privacy though.
First question: does this mean I won't be able to publish patches to the package?
Why do I not want this package under my control? The original package simply calls spawn for your real `ssh-keygen` with the appropriate arguments. No real problem, (although there is very little value here). But a contributor added support for Windows by uploading opaque binary builds for Windows. While I have no reason to distrust the contributor, it is scary to be "responsible" for opaque executables that I did not personally produce.
So, what should I do with this package? Assuming npm lets me do anything?
Fortunately this package is "only" downloaded ~1600 times/week, miniscule for npm. If you are tempted to use ssh-keygen, I recommend you learn how to use execFile/spawn, and use the native program directly.
For context, I published this 10 years ago, as one of my earliest contributions to open source. I probably wouldn't have gone near any security-essential contributions if I had more experience at the time.
> "only" downloaded ~1600 times/week
This begs for an audit.
If npm lets me publish a new version, I'd be happy to remove the Windows binaries.
These kinds of checks are so trivially defeated, the only people they actually stop is people trying to do legitimate work.
K⃞ e⃞ y⃞ g⃞ e⃞ n⃞
Ⓚⓔⓨⓖⓔⓝ кєץﻮєภ Nguyen ᏦᏋᎩᎶᏋᏁ kēฯງēຖ 𝐊𝐞𝐲𝐠𝐞𝐧 𝗞𝗲𝘆𝗴𝗲𝗻 𝘒𝘦𝘺𝘨𝘦𝘯 𝙆𝙚𝙮𝙜𝙚𝙣 𝙺𝚎𝚢𝚐𝚎𝚗
What's the issue with ssh-keygen? gpg --gen-key?
This is just some ridiculous NPM policy. What will be next? Cracks?
Can someone please explain this to me?
Thank you for my daily memento morì.
But you keep using it.
I refuse to use it at work and refuse to use it in personal life. It’s not real software and will cause you harm.
I went to my bank, Bank of America, and they claimed that there was nothing they could do because NPM was using some sort of option they had to follow me when I got new credit cards. I don't know what kind of option that is, as every time I get a new credit card I have to update it with literally every other company. I also don't know how a bank wouldn't have some sort of manual override. Nevertheless, I called NPM, who said I had to talk with my bank. Eventually, after months of dealing with this loop, I threatened to leave my bank, and my bank advised me to call them and threaten to get the BBB involved if they didn't fix it, and a few days later NPM admitted it was an error on their end and reversed all of the charges.
To this day I wonder what kind of shady thing NPM was doing to not just charge someone who had never been a customer of theirs, but to follow them across cancelled credit cards.
If you merely got a new expiration date, security code, etc. without also changing the card number, they could "follow" that by submitting a transaction without those extra pieces of information, at greater cost and risk to themselves, though.
I'll happily take downvotes if I'm wrong, for being assertive without a source.
Are you sure NPM was actually charging your card directly, and not a digital wallet or similar virtual card thing which you kept active?
It's very convenient if that's what you want -- it means you don't have to go to all of the ongoing services to update your card immediately. But it does mean that you can't count on changing a card to stop unwanted ongoing charges.
I recently replaced a card at my bank, and they offered this as an opt-in service (which I opted in to), but I hear that some banks make it opt-out, instead.
NPM was in the wrong for continuing to place unwanted transactions, but they were not actively participating in this "follow" scheme so the blame stops short of that.
The way the update services is work is that you send them the card type, card number, and expiration date of a card you have on file, and they respond typically with one of these four responses:
1. Still good.
2. The account is closed.
3. The card is still good but has a new expiration date, which is YYMM.
4. The account has a new card. The card number is XXXXXXXXXXXXXXXX and the expiration date is YYMM.
The existence of #4 seems odd though. If someone just wanted different card perks they could do a "product change" which I believe retains the same number anyway, so a new number should only occur if the old number was reported stolen, in which case why provide the new number to the potential thief?
For a typical user who has their card stolen it will go something like this. Fraudulent charges start appearing on their card, which is when they realize their card number has been stolen. The bank issues them a new card, makes sure the fraudulent charges get refunded, and invalidates the old card so the thieves won't be able to put new charges on it.
Without the updater service the user would have to deal with contacting every place they have subscriptions and update their on file card to avoid having their services disrupted.
With the updater service many or most of those will update automatically.
If the thieves used the card to buy some subscriptions, and those are from merchants who are able to use the update services, then those services may get the new number so the user might have to contact them to cancel.
For most people in that case though the number of subscriptions they legitimately have will be much less than the number of subscriptions that the credit card thieves purchased on the user's stolen card.
"Stripe works with card networks and automatically attempts to update saved card details whenever a customer receives a new card (for example, replacing an expired card or one that was reported lost or stolen)."
https://stripe.com/docs/saving-cards#:~:text=Automatic%20car...).
I found the email from NPM when they fixed it, though in the email they still claim that my card details were stolen and it should be closed, ignoring that I had done that multiple times already. The email is below. Apparently there were 28 charges, so it must have been around 2 years that this was ongoing, I was dealing with some major issues at that time so I had to put it on the backburner for that time.
As far as digital wallets and virtual cards, I have none of those things. I may be a programmer, but I haven't gone techy with my finances, I just have a checking account and a credit card, and this charge kept appearing on my credit card across at least two card cancellations. Having said that, I have no idea what would happen if a fraudulent digital wallet or virtual card was set up that I was unaware of. The issue did start in 2015 though, so I'm not sure if those even existed back then.
Email from <Redacted>@npmjs.com: "We've completed the investigation into the charges we believe linked to your card ending in [Redacted]. We've refunded each individual charge for a total of $196 (28 refunds at $7/each). You should see those credited back to your account within a few business days.
We've canceled the subscription the charges were linked to, and removed the billing details. That said, we'd still encourage you to notify your bank that the card information was stolen and that the card should be closed.
Thanks for your patience while we worked through this on our end. I understand it wasn't ideal and even frustrating at times. I'm sorry for that.
Please let us know if there is anything else we can do for you. We’ll be here to help."
There are many legitimate purposes for postinstall scripts yet the anti-postinstall crowd acts like they solved security issues with this one easy step.
They are a very bad thing.
I can't square this circle of someone being paranoid about postinstall script but at the same time thinks the first chance to review dependency code is after doing a `npm i`.
Check the git repo of the library you are installing beforehand if you're so paranoid about postinstall.
And above that, never install any library for which the source is not readily available. This is the most basic first line of defense.
username checks out.
> And above that, never install any library for which the source is not readily available.
Whether source is available or not is mostly irrelevant when you're potentially dealing with malicious code, you need to review artifacts that are being fetched from NPM since those can differ from source code on Github.
Attackers aren't going to announce their malicious code through meaningful git commit messages in a prominently displayed GitHub repository. They will make innocent-looking commits on Github, then publish a new version containing a single additional line of malicious code on NPM.
True. How about people act their threat model? Instead of removing a feature for many users, just do whatever you need to do to be sure you're safe yourself?
In what other major situation is the solution to nuke a feature due to security concerns?
Afaik the main conversation about postinstall is around leeches complaining about political messages in their console and one or two other incidents
Yes it is good to never install malicious NPM packages anyway but if you develop for any of those runtimes and you do not bother to check dep tree the anti install script crowd saved your ass.
So a completely different scenario? Let's assume for a moment that developers only ever 'build' or 'check' their code, but all actual runtime behavior is in production. In production we have toooooons of security tooling for monitoring and constraining program behavior. On dev computers? Basically nothing.
Of course, developers run `test` as well, and sometimes they run the whole program but these use cases, especially at companies, are increasingly moving to CI.
Please, make sure it runs locally first. CI often costs $$$, and when you nab a QA for debugging support, nothing irritates more than the answer "Well, no..." to the question "Did you even compile/run this?"
Uh... branches? Obviously?
The intent is almost certainly to stop a spam campaign which was using NPM package pages to host links to outside sites. Similar pages have been discussed on HN previously [1].
The fact that there was actual installable software involved was irrelevant to the attacker. All they were after was a way to put their content on a high-reputation domain -- and NPM was perfect for that.
> You are correct, keygen is a stopword. We blocked users from using this word for security purposes.
> Apologize for the inconvenience and we highly suggest you choose a different word for your package going forward.
Don't expect to see KMS spoofers on GitHub anytime soon for the same reason.
KMS spoofers are the services running on those internet hosts the scripts talk to.
py-kms is on GitHub but I assume it won't remain there for the same reasons as yt-dlp.
You mean this yt-dlp that isn't on there? https://github.com/yt-dlp/yt-dlp
That script also does more than just Online KMS activation, which would be clear from a few seconds skimming.
There's also been no indication that any of these repos would get taken down. At all. py-kms has been there since 2017. You'd think if Microsoft had such a big problem with its existence, it'd have gotten pulled in the last 6 years.
But I'm still curious why keygen would be problematic as part of a package name?