GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Ars Technica (arstechnica@mastodon.social)'s status on Tuesday, 05-Nov-2024 18:13:38 JST Ars Technica Ars Technica

    JavaScript developers targeted by hundreds of malicious code libraries
    These are not the the developer tools you think they are.
    https://arstechnica.com/security/2024/11/javascript-developers-targeted-by-hundreds-of-malicious-code-libraries/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

    In conversation 9 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/427/282/612/360/949/original/43b3125f7ef633f1.jpg
    2. Domain not in remote thumbnail source whitelist: cdn.arstechnica.net
      Hundreds of code libraries posted to NPM try to install malware on dev machines
      These are not the the developer tools you think they are.
    • Charlie Stross and Xenotar repeated this.
    • Embed this notice
      JohnMashey (johnmashey@mstdn.social)'s status on Tuesday, 05-Nov-2024 18:13:38 JST JohnMashey JohnMashey
      in reply to

      @arstechnica
      Reminder of Ken Thompson’s 1984 Turing lecture, Reflections in Trusting Trust, about a1975 hack:
      https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf
      It’s even more relevant now given the greatly-increased layers of software used by programmers.
      Tidbit: AFAIK, out group was the only one to notice this hack, which occurred a few weeks after I’d read John Brunner’s The Shockwave Rider & laughed prematurely at idea of worms with infinitely-replicating tails.

      In conversation 9 months ago permalink

      Attachments


Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.

Embed this notice