HNHacker News
TopNewBestAskShowJobs

feross

48,015 karma · joined September 1, 2009

Founder & CEO, Socket <https://socket.dev> – Socket makes a developer-first security platform that prevents vulnerable and malicious open source dependencies from infiltrating your software supply chain.

Stanford visiting lecturer, CS 253 Web Security <https://cs253.stanford.edu> – Principles of web security, attacks and countermeasures, and more...

Open source maintainer – 100+ open source packages on npm, including WebTorrent <https://webtorrent.io>, StandardJS <https://standardjs.com>, BitMidi <https://bitmidi.com>, simple-peer <https://github.com/feross/simple-peer>, and more <https://socket.dev/npm/user/feross>.

You can reach me at {my username}@feross.org, or find out more on my website: https://feross.org/resume

[ my public key: https://keybase.io/feross; my proof: https://keybase.io/feross/sigs/gO6pVIJ1DXdy9Y21yil6nlyk_by5BE_GaaWOOQJ5PvQ ]

submissionscomments
feross··on The Everything NPM Package
Founder of socket here. npm has since unpublished the chunk packages that the 'everything' package depends on (or perhaps made them private), so those packages are no longer being taken into account in the package score.

You're right that a package that depends on literally everything would absolutely have a score of 0 in our system.

feross··on Is Running Random Code from NPM Safe?
Do it! This sounds fun :)

Reminds me of an idea I had a while back: create a VM running Windows XP (without service packs, and crawl the web downloading and executing every .exe file that is found. Wait and see what happens to the machine.

feross··on Snyk still reporting hacked Ledger package is safe, 12 hours after compromise
The service my company runs, Socket, also only analyzes your manifest files.

Socket is designed to work without the need to analyze, upload, or share your source code. The only data we collect from your repository are the manifest files (package.json, package-lock.json, yarn.lock, etc.).

We use the dependency snapshot to determine the list of packages used by your repository, perform our open source risk analysis, and produce a report.

More info here: https://docs.socket.dev/docs/faq

feross··on Ledger's NPM account has been hacked
Thanks for reporting this. Fixed: https://socket.dev/npm/package/@ledgerhq/connect-kit-loader/...

We don't currently detect 'implicit dependencies' loaded via CDN URLs, though we'll look into what it would take to support this.

feross··on Ledger's NPM account has been hacked
We've built our own minimalist static analysis engine that only supports scanning for the specific supply chain threats we care about. For that reason, it's a lot simpler and faster than a generic engine.

I'll see if we can write up a bit about how it works in a future blog post.

feross··on Ledger's NPM account has been hacked
This isn't quite accurate. In fact, npm did ship a form of code signing called 'npm provenance' in April 2023. We wrote a semi-official deep dive on the feature in cooperation with the npm team that explains how to sign your npm packages [1].

You can see npm provenance in action on this npm package page [2] if you scroll to the very bottom and look under the "Provenance" heading.

[1]: https://socket.dev/blog/npm-provenance

[2]: https://www.npmjs.com/package/@socketsecurity/cli

feross··on Ledger's NPM account has been hacked
Yes, please get in touch with me at (my_username)@socket.dev.
feross··on Ledger's NPM account has been hacked
We've been building Socket [1] to detect and block this exact type of supply chain attack. Our Socket AI scanner [2] successfully detected this attack. It uses dozens of static signals combined with an LLM to detect novel attacks that evade traditional scanning tools.

This is what Socket AI produces when given @ledgerhq/connect-kit 1.1.7 to analyze:

> The obfuscated code block is highly suspicious and likely contains malicious behavior. The presence of obfuscation and the unclear purpose of the code raise significant red flags.

Feeling very proud of our team right now as this validates that our static analysis + LLM approach works well on novel malicious dependencies. If you're interested, we maintain a listing of malicious packages detected by this system [3].

Small plug: If you’d like real-time protection against attacks like this, you can install Socket for GitHub to automatically scan every PR in your repo. The free plan is incredibly generous. If you do decide to install it, it’s important that you enable the ‘AI Detected Security Risk’ alert type in your Security Policy to activate this protection.

[1]: https://socket.dev

[2]: https://socket.dev/blog/introducing-socket-ai-chatgpt-powere...

[3]: https://socket.dev/npm/issue/malware

feross··on SSH keys stolen by stream of malicious PyPI and NPM packages
If you're curious to see what's going inside these malicious PyPI and NPM packages, we host a catalog of all removed packages for research use. Here are links to some examples of the cached malicious source code, along with the signals of malicious intent detected by Socket:

https://socket.dev/npm/package/shineouts/files/1.12.16-beta....

https://socket.dev/npm/package/@dynamic-form-components/shin...

https://socket.dev/npm/package/eslint-plugin-shein-soc-raw/f...

https://socket.dev/npm/package/@spgy/eslint-plugin-spgy-fe/f...

If you're curious to see more examples of the kind of malicious stuff that is posted regularly to package registries, we have a live updating list here: https://socket.dev/npm/issue/gptSecurity

[Disclosure: I'm founder of Socket]

feross··on Ask HN: Who is hiring? (December 2023)
Socket (https://socket.dev) | Staff Software Engineer & Security Researcher | SF or REMOTE | Full-time

If you specialize in making computers do things they’re not supposed to do, please drop us a line.

Socket's mission is to help developers and security teams to ship faster and spend less time on security busywork. Thousands of organizations use Socket to safely discover, audit, and manage their open source code. Our customers – from Figma to Vercel – absolutely love Socket (just read their tweets to see for yourself! [1])

The company was founded by Feross Aboukhadijeh [2], who has worked in open source software for 10+ years writing software that receives more than a billion downloads per month. We have raised $25M in funding [3] from the best angel investors, operators, and security leaders in the industry.

We're a small team (~15) but we're already depended on by top companies like Figma, Vercel, Brave, Replit, Expo, Metamask, a massive telecom in Canada, as well as three massive AI companies that you've definitely heard of ;)

See all job openings here: https://socket.dev/careers

[1]: https://socket.dev/love

[2]: https://www.linkedin.com/in/feross/

[3]: https://socket.dev/blog/series-a

feross··on Show HN: I saw this mind-blowing experiment, so I made a simple version of it
It’s not malware, I promise. Just super annoying :)

Source code: https://github.com/feross/TheAnnoyingSite.

feross··on Socket lands $20M investment to help companies secure open source software
Founder of Socket here :) I'll be around for the next several hours to answer questions.
feross··on Show HN: Socket web extension – free NPM supply chain protection
We have that too :)

https://docs.socket.dev/docs/socket-cli

feross··on Show HN: Socket web extension – free NPM supply chain protection
You can see some examples of the output of the ML model in the scrolling threat feed on our homepage here: https://socket.dev

We use LLMs both for detecting threats as well as explaining the output of traditional static analysis in a way that makes the findings understandable to the average developer.

feross··on Show HN: Socket web extension – free NPM supply chain protection
There is a website here https://socket.dev where you can search for any OSS package and get the same information without the need for an extension.

The idea behind the extension is that it integrates directly into the developer workflow so you don’t have to remember to check a separate website.

feross··on Ask HN: Could you share your personal blog here?
https://feross.org though I mostly blog at https://socket.dev these days.
feross··on A Driverless Ride with Waymo’s CPO
The video made it seem like the mics were on the _outside_ of the vehicle. But now I wonder if that's true.
feross··on JavaScript registry NPM vulnerable to 'manifest confusion' abuse
Sorry if I'm misunderstanding, but how is this the same issue discussed in the article?
feross··on JavaScript registry NPM vulnerable to 'manifest confusion' abuse
tldr; This issue allows an attacker to include a 'hidden dependency' in a package that won’t show up on the npm website, even though the CLI will actually install it.

The issue is caused by a disparity between a package's manifest and its tarball contents, which npm does not enforce are consistent. And unfortunately, a lot of data – such as the dependencies, install scripts, license, etc. – is duplicated between the package.json in the tarball and the metadata served by registry.npmjs.org. And every tool uses a different source of truth.

Socket (disclosure: my startup), I'm proud to say, has been using the correct manifest file - the package.json inside the tarball - for all security analysis, which aligns with the installation behavior of every major package manager. This means any attempt to exploit this technique would not have evaded Socket’s analysis. We wrote more about manifest confusion here: https://socket.dev/blog/manifest-confusion

feross··on Theseus DHT Protocol (2018)
bittorrent-dht: https://github.com/webtorrent/bittorrent-dht (JavaScript implementation used by WebTorrent)
feross··on NPM Registry Code Signing
Agreed - people have wanted this feature on npm for a very long time. But code signing has it's limits, as the post mentions. Still, it's a valuable tool and there's no reason not to do it.
feross··on 50% of new NPM packages are spam
Speaking as CEO at https://socket.dev, we’d love to partner with GitHub on an initiative like this.
feross··on Silicon Valley Learns to Love Socialism for the Rich
What did the depositors do wrong? You're saying in a just world, the individuals and businesses who just decided to open a checking account—at a top-20 US bank—deserve to lose everything? What did they do wrong?
feross··on Silicon Valley Learns to Love Socialism for the Rich
> One SVB depositor, the streaming service Roku, has $487 billion housed in the bank—only a small fraction of which seems to be insured.

Not impressed by the basic factual errors in this article. $487 billion ≠ $487 million. https://variety.com/2023/digital/news/roku-svb-failed-silico...

EDIT: I just noticed another disappointing factual error, bordering on disinformation. They say:

> On October 14, 2022, Sacks tweeted, “The idea that the American government, the American taxpayer, or any American company is obligated to provide support is pre entitlement.” That was before the SVB collapse. On March 10, 2023, Sacks sang a different tune: “Where is Powell? Where is Yellen? Stop the crisis NOW. Announce that all depositors will be safe.”

I'm no Sacks apologist, but they took his first quote completely out-of-context, making it sound like he was saying the US government shouldn't support failing companies, when he was in fact talking about the US supporting Ukraine. See: https://twitter.com/DavidSacks/status/1634357137873969152

feross··on Show HN: Protect your Python app from an OSS supply chain attack
Exactly one year ago I announced Socket (https://news.ycombinator.com/item?id=30515090), a simple, developer-friendly GitHub App that protects your JavaScript apps from software supply chain attacks. Since then, thousands of organizations have adopted Socket – including Vercel, Brave, BBC, Expo, Storybook, Replit, Metamask – and many more.

Today, I am incredibly excited to announce that Socket now supports Python!

Python is one of the most popular programming languages in the world, with millions of developers using it for everything from data science to web development. However, like all open source software, Python packages are vulnerable to supply chain attacks.

Most "vulnerability scanning" tools merely look up the packages you're using to see if any vulnerabilities have been reported to public CVE databases, an approach that is noisy and riddled with false positives.

Socket takes an entirely new approach. Socket uses "deep package inspection" to peel back the layers of a dependency and characterize its actual behavior. This allows us to detect and block likely supply chain attacks before they strike, mitigating the worst consequences.

With Socket, you don't have to worry about alert fatigue or wasting time sifting through piles of meaningless alerts. By default, Socket only alerts you on the most critical security issues – potential supply chain attacks, known malware, typosquats, and other similarly severe issues.

This means you can focus on what matters most – building great software – while Socket takes care of the security side of things. Let me know if you have questions and I'll be happy to answer them.

feross··on Supply Chain Attack Using PyPI Packages “Colorslib”, “Httpslib”, and “Libhttps”
This is exactly what we provide at Socket. See https://socket.dev

We flag anything a package introduces new install scripts, network, etc.

feross··on Compromised PyTorch-nightly dependency chain between December 25th – December 30
We're solving this problem at https://socket.dev starting with npm, with python coming in the next month or two. Here's an example of a date picker web component that runs an install script, collects telemetry, accesses the network and filesystem, and more -- all detected with our static analysis engine. https://socket.dev/npm/package/angular-calendar

We show alerts in GitHub pull requests, or the CLI, if you add a dependency with a supply chain risk.

feross··on Bugout: Browser-to-browser networking built on WebTorrent
Yes. For files up to 5 GB, Wormhole stores your files on our servers for 24 hours.
feross··on Bugout: Browser-to-browser networking built on WebTorrent
For #2, see https://wormhole.app which is built with the same WebTorrent library mentioned in the original link. Works on iOS, Android, etc. all platforms as far as I know.

Disclosure: worked on WebTorrent and Wormhole.app

feross··on Bugout: Browser-to-browser networking built on WebTorrent
It’s cool to see folks using WebTorrent tracker servers to bootstrap p2p connections for other apps. I’ve also seen some native apps doing this with the mainline BitTorrent DHT.

Disclosure: I’m the original author of WebTorrent

← PreviousPage 2 of 16Next →