HNHacker News
TopNewBestAskShowJobs

carols10cents

594 karma · joined October 27, 2010

Carol Nichols, carol-nichols.com. co-author of https://www.nostarch.com/rust and https://www.manning.com/livevideo/rust-in-motion?a_aid=cnichols&a_bid=6a993c2e
submissionscomments
carols10cents··on AUR packages compromised with Infostealer and Rootkit
How does a user become a Trusted User? Who is paying them to review everything?
carols10cents··on Decisions that eroded trust in Azure – by a former Azure Core engineer
If you're writing the tests after writing the code, you're not doing TDD though.
carols10cents··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
Since Shai-Hulud scanned maintainers' computers, if the signing key was stored there too (without a password), couldn't the attackers have published signed packages?

That is, how does signing prevent publishing of malware, exactly?

carols10cents··on Crates.io phishing attempt
Yeah, npm has orders of magnitude more users than crates.io. This attack's success, or lack thereof, has no bearing on the savviness of JavaScript or Rust developers.
carols10cents··on Malicious versions of Nx and some supporting plugins were published
So why are you upgrading?
carols10cents··on Malicious versions of Nx and some supporting plugins were published
Who is requiring you to use large numbers of transitive dependencies? You can always write all the code yourself instead.
carols10cents··on Why is everybody knitting chickens?
Why wouldn't you knit a chicken???
carols10cents··on When Compiler Engineers Act as Judges, What Can Possibly Go Wrong?
And the architect is a volunteer for Habitat for Humanity.
carols10cents··on Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos
who is going to pay for the review of packages and updates? how do we know we can trust the reviewers?

github actions are name-spaced and that didn't help anything here...

carols10cents··on Rust Just Failed an Important Test
Do not try to equalize a maintainer guarding their time and energy from having to deal with an issue that has already been fixed and users that refuse to search or read with trying to cover up for gross negligence and bugs.
carols10cents··on Rust Just Failed an Important Test
No maintainer is obligated to maintain access to a discussion space for their users.

> One now doesn't even know and cannot even estimate the number of other issues that must have gone unreported. It's not safe or wise to use a package that is so shrouded in mystery. It is in fact foolhardy.

Issues don't get reported for any number of reasons. All open source is use at your own risk.

carols10cents··on Fern Hollow Bridge should have been closed years before it collapsed
It's the Charles Anderson Bridge. https://engage.pittsburghpa.gov/charles-anderson-bridge
carols10cents··on Timeline of the xz open source attack
What would prevent the sock puppet accounts from signing each others' keys?
carols10cents··on C++ creator rebuts White House warning
How are these two problems unique to Rust though?
carols10cents··on Show HN: Little Fixes – a spatial forum to improve your city
It looks like accounts can be entirely anonymous. How are you planning on handling moderation of comments? What happens if I post on a neighbor's house "jagoff who lets their dogs poop everywhere lives here, please evict"?
carols10cents··on When every ketchup but one went extinct (2022)
Tell me you don't know anyone from Pittsburgh without telling me you don't know anyone from Pittsburgh.
carols10cents··on Standards for Software Liability: Jim Dempsey, Lawfare, UC Berkeley Law
> these are the folks who do the Lawfare podcast, right?

Yep, and they had a podcast episode with the author of this paper: https://www.lawfaremedia.org/article/the-lawfare-podcast-jim...

carols10cents··on How Australia’s ‘Bluey’ conquered children’s entertainment
I wish Bluey hadn't introduced the concept of a "bush wee" to my kid, I've had to explain that no, we can't pee in someone's yard in the middle of our busy neighborhood...
carols10cents··on Was Rust Worth It?
Namespaces can't be typosquatted?
carols10cents··on Was Rust Worth It?
Crates.io has publisher information-- namespacing is not required for that. For example, here are all the crates owned by the `azure` GitHub organization and published by the `azure-sdk-publish-rust` team: https://crates.io/teams/github:azure:azure-sdk-publish-rust
carols10cents··on Was Rust Worth It?
How do namespaces measurably increase security?
carols10cents··on Rust Malware Staged on Crates.io
I'm one of the crates.io team members, and we're very grateful to Phylum for doing this analysis and alerting us!

As a volunteer member, I'm also very thankful to the Rust Foundation for funding and hiring Walter Pearce, Adam Harvey, and Tobias Bieniek to work on security and crates.io (in varying proportions). They've helped lower our response time to incidents like this and made proactive improvements.

Regardless of any improvements they have or will make, there's always the possibility of malware getting through defenses. Reports are important to us, taken seriously, and handled as promptly as possible. More details here: https://www.rust-lang.org/policies/security

carols10cents··on Compromised PyTorch-nightly dependency chain between December 25th – December 30
Making crev part of the official Rust toolchain won't magically make enough time in the day for me to want to volunteer any of it doing code review.
carols10cents··on There is no “software supply chain”
That's what TideLift's goals are too. https://tidelift.com/
carols10cents··on Rust stabilizes generic associated types
You're very welcome, I'm glad you like it! <3
carols10cents··on Rust stabilizes generic associated types
Hi! Book author here. I think the other comments were answering when the feature will be available in a stable release. No content has been written for this, and it's not entirely clear to me yet how best to work this into the book.

The RFC is probably the best documentation for now.

carols10cents··on Bridge collapse in Pittsburgh’s Frick Park
No. This was released yesterday: https://pittsburghpa.gov/press-releases/press-releases/5590
carols10cents··on Solving Open Source Supply Chain Security for the PHP Ecosystem
> Hang your shingle out by publishing negative (vote-against) attestations of vulnerable versions of open source software and positive attestations (e.g. code-review) of the versions that mitigated the issues they disclosed.

So you're imagining that a bunch of people trying to break into security work will do work for free in hopes of gaining potential employers'/clients' trust?

And you're imagining that this ecosystem of attestations will be seeded by a bunch of people looking to gain the community's trust?

So who audits the auditors? And how long do you expect it to take to get a critical mass of people reviewing code who have gained the community's trust to be reviewing enough packages to solve open source supply chain security?

carols10cents··on Is It Even Worth Working on FOSS Anymore?
Yup, this. And in places where logging companies aren't ruining forests, it's because of government regulation.
carols10cents··on Show HN: Cleanvoice – Automated Podcast Editing
Yes, the worst is when so much silence is removed that it sounds like someone is laughing over themselves.
Page 1 of 6Next →